Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23936 Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: STAR_Labs

Published:

Updated: 2024-09-05T19:55:42.789Z

Reserved: 2023-03-30T09:14:16.052Z

Link: CVE-2023-1713

cve-icon Vulnrichment

Updated: 2024-08-02T05:57:24.863Z

cve-icon NVD

Status : Modified

Published: 2023-11-01T10:15:08.973

Modified: 2024-11-21T07:39:45.037

Link: CVE-2023-1713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses