PT-2023-6691 · Bitrix+1 · Bitrix24+1
Cursered
+2
·
Published
2023-11-01
·
Updated
2023-11-09
·
CVE-2023-1717
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bitrix24 version 22.0.300
Description
The issue is related to prototype pollution in the bitrix/templates/bitrix24/components/bitrix/menu/left vertical/script.js component of Bitrix24. This allows remote attackers to execute arbitrary JavaScript code in the victim's browser and possibly execute arbitrary PHP code on the server if the victim has administrator privileges. The exploitation is done by polluting
proto [tag] and proto [text].Recommendations
For Bitrix24 version 22.0.300, consider disabling the script.js component temporarily until a patch is available to prevent exploitation. Restrict access to the bitrix/templates/bitrix24/components/bitrix/menu/left vertical/script.js file to minimize the risk of exploitation. Avoid using the
proto [tag] and proto [text] variables in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Prototype Pollution
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitrix
Bitrix24