PT-2023-6687 · Bitrix+1 · Bitrix24+1
Lam Jun Rong
+1
·
Published
2023-11-01
·
Updated
2025-12-01
·
CVE-2023-1714
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bitrix24 version 22.0.300
Description
An unsafe variable extraction issue exists in the
bitrix/modules/main/classes/general/user options.php file. This allows remote authenticated attackers to execute arbitrary code through two methods: appending arbitrary content to existing PHP files, or PHAR deserialization. The issue involves incorrect external control of the file name or path. Exploitation may allow an attacker to execute arbitrary code and elevate privileges.Recommendations
Bitrix24 version 22.0.300: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitrix
Bitrix24