VYPR
Medium severity4.9NVD Advisory· Published Nov 4, 2024· Updated Jul 5, 2026

CVE-2024-34882

CVE-2024-34882

Description

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Bitrix/Bitrix24llm-fuzzy3 versions
    23.300.100+ 2 more
    • (no CPE)range: 23.300.100
    • cpe:2.3:a:bitrix24:bitrix24:23.300.100:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.