PT-2023-6687 · Bitrix+1 · Bitrix24+1
Lam Jun Rong
+1
·
Publicado
2023-11-01
·
Atualizado
2025-12-01
·
CVE-2023-1714
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bitrix24 version 22.0.300
Description
An unsafe variable extraction issue exists in the
bitrix/modules/main/classes/general/user options.php file. This allows remote authenticated attackers to execute arbitrary code through two methods: appending arbitrary content to existing PHP files, or PHAR deserialization. The issue involves incorrect external control of the file name or path. Exploitation may allow an attacker to execute arbitrary code and elevate privileges.Recommendations
Bitrix24 version 22.0.300: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bitrix
Bitrix24