NA

CVE-2023-1714

Published: 01/11/2023 Updated: 09/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated malicious users to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.

Vulnerable Product Search on Vulmon Subscribe to Product

bitrix24 bitrix24 22.0.300

Github Repositories

Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction

CVE-2023-1714 Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction Unsafe variable extraction in bitrix/modules/main/classes/general/user_optionsphp in Bitrix24 220300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization starlabssg/advisories/23/23-171