CVE-2023-30253
CVSS 8.8 HIGH: dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP… EPSS 82% (100th percentile).
Vulnerabilities & Exploits
Public exploit modules change the risk from theoretical to repeatable. Once a flaw lands in Metasploit, unpatched systems stop being obscure findings and become low-effort targets for opportunistic attackers. That is the real shift here, not the CVE announcements themselves.
Rapid7 added modules for Marvell QConvergeConsole CVE-2025-6793, GestioIP 3.5.7 CVE-2024-48760, and Dolibarr ERP/CRM CVE-2023-30253. The GestioIP issue is an authenticated unsafe upload handler flaw that can be pushed into remote code execution, and the QConvergeConsole module reads arbitrary files from versions 5.5.0.85 and earlier.
The new Vim plugin persistence technique widens the story beyond single-product bugs. It gives defenders another reason to watch Unix workstations and developer systems, because persistence can now be hidden in a normal editor plugin path.
1 source · May 15
CVSS 8.8 HIGH: dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP… EPSS 82% (100th percentile).
CVSS 9.8 CRITICAL: an issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. EPSS 45% (99th percentile).
CVSS 9.4 CRITICAL: marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. EPSS 17% (97th percentile).
Rapid7
Metasploit Wrap-Up 05/15/2026
New Metasploit modules detail critical vulnerabilities, including an unauthenticated path traversal in Marvell QConvergeConsole (CVE-2025-6793).
originalPart of the PlainSec briefing for 2026-05-15
Every edition of this story: Metasploit Modules Turn Old CVEs Into Routine Targets