VYPR
Medium severity6.8NVD Advisory· Published Nov 4, 2024· Updated Jul 5, 2026

CVE-2024-34885

CVE-2024-34885

Description

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Bitrix/Bitrix24llm-fuzzy3 versions
    23.300.100+ 2 more
    • (no CPE)range: 23.300.100
    • cpe:2.3:a:bitrix24:bitrix24:23.300.100:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.