Unrated severityNVD Advisory· Published Nov 1, 2023· Updated Sep 5, 2024
Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction
CVE-2023-1714
Description
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- starlabs.sg/advisories/23/23-1714/mitrethird-party-advisory
News mentions
0No linked articles in our index yet.