VYPR
Medium severity6.8NVD Advisory· Published Nov 4, 2024· Updated Jul 5, 2026

CVE-2024-34891

CVE-2024-34891

Description

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Bitrix/Bitrix243 versions
    cpe:2.3:a:bitrix24:bitrix24:23.300.100:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:bitrix24:bitrix24:23.300.100:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: = 23.300.100

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.