Medium severity4.9NVD Advisory· Published Jan 20, 2023· Updated Jun 17, 2026
CVE-2022-43959
CVE-2022-43959
Description
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- www.bitrix24.com/prices/self-hosted.phpnvdVendor Advisory
- www.bitrix24.com/security/nvdVendor Advisory
News mentions
0No linked articles in our index yet.