PT-2023-6693 · Bitrix+1 · Bitrix24+1

Lam Jun Rong

+1

·

Publicado

2023-11-01

·

Atualizado

2023-11-08

·

CVE-2023-1715

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bitrix24 version 22.0.300
Description A logic error in the mb strpos() function allows attackers to bypass XSS sanitization by placing HTML tags at the beginning of the payload, potentially leading to a cross-site scripting (XSS) attack. This issue is related to the failure to neutralize scripts in attributes on web pages.
Recommendations For Bitrix24 version 22.0.300, consider disabling the mb strpos() function until a patch is available to prevent exploitation of this issue. Restrict access to any modules or functions that utilize the mb strpos() function to minimize the risk of XSS attacks. Avoid using HTML tags at the beginning of any payload in the affected version to reduce the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07463
CVE-2023-1715

Produtos afetados

Bitrix
Bitrix24