PT-2023-6691 · Bitrix+1 · Bitrix24+1

Cursered

+2

·

Published

2023-11-01

·

Updated

2023-11-09

·

CVE-2023-1717

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bitrix24 version 22.0.300
Description The issue is related to prototype pollution in the bitrix/templates/bitrix24/components/bitrix/menu/left vertical/script.js component of Bitrix24. This allows remote attackers to execute arbitrary JavaScript code in the victim's browser and possibly execute arbitrary PHP code on the server if the victim has administrator privileges. The exploitation is done by polluting proto [tag] and proto [text].
Recommendations For Bitrix24 version 22.0.300, consider disabling the script.js component temporarily until a patch is available to prevent exploitation. Restrict access to the bitrix/templates/bitrix24/components/bitrix/menu/left vertical/script.js file to minimize the risk of exploitation. Avoid using the proto [tag] and proto [text] variables in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Prototype Pollution

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-07461
CVE-2023-1717

Affected Products

Bitrix
Bitrix24