Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-34887

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.
Attacker Value
Unknown

CVE-2024-34883

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.
Attacker Value
Unknown

CVE-2024-34882

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.