PT-2023-6687 · Bitrix+1 · Bitrix24+1

Lam Jun Rong

+1

·

Publicado

2023-11-01

·

Atualizado

2025-12-01

·

CVE-2023-1714

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bitrix24 version 22.0.300
Description An unsafe variable extraction issue exists in the bitrix/modules/main/classes/general/user options.php file. This allows remote authenticated attackers to execute arbitrary code through two methods: appending arbitrary content to existing PHP files, or PHAR deserialization. The issue involves incorrect external control of the file name or path. Exploitation may allow an attacker to execute arbitrary code and elevate privileges.
Recommendations Bitrix24 version 22.0.300: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07457
CVE-2023-1714

Produtos afetados

Bitrix
Bitrix24