Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2023-1714
Disclosure Date: November 01, 2023 (last updated November 10, 2023)
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
0
Attacker Value
Unknown
CVE-2023-1713
Disclosure Date: November 01, 2023 (last updated November 10, 2023)
Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
0
Attacker Value
Unknown
CVE-2022-43959
Disclosure Date: January 20, 2023 (last updated February 24, 2025)
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
0
Attacker Value
Unknown
CVE-2022-27228
Disclosure Date: March 22, 2022 (last updated February 23, 2025)
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-13484
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
0
Attacker Value
Unknown
CVE-2020-13483
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
0
Attacker Value
Unknown
CVE-2020-13758
Disclosure Date: June 01, 2020 (last updated February 21, 2025)
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
0