PT-2024-7263 · 1с · Bitrix24+1
Oleg Labyntsev
+1
·
Published
2024-04-23
·
Updated
2024-11-06
·
CVE-2024-34882
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
1C-Bitrix Bitrix24 version 23.300.100
Description
The issue concerns insufficiently protected credentials in SMTP server settings, allowing remote administrators to send SMTP account passwords to an arbitrary server via an HTTP POST request. This could enable a remote attacker to gain access to authentication data from the SMTP server.
Recommendations
For version 23.300.100, update to the latest patch version immediately and rotate compromised credentials. As a temporary workaround, consider restricting access to the SMTP server settings to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitrix24
Bitrix