PT-2023-6687 · Bitrix+1 · Bitrix24+1

Lam Jun Rong

+1

·

Published

2023-11-01

·

Updated

2025-12-01

·

CVE-2023-1714

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bitrix24 version 22.0.300
Description An unsafe variable extraction issue exists in the bitrix/modules/main/classes/general/user options.php file. This allows remote authenticated attackers to execute arbitrary code through two methods: appending arbitrary content to existing PHP files, or PHAR deserialization. The issue involves incorrect external control of the file name or path. Exploitation may allow an attacker to execute arbitrary code and elevate privileges.
Recommendations Bitrix24 version 22.0.300: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-07457
CVE-2023-1714

Affected Products

Bitrix
Bitrix24