Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23937 Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: STAR_Labs

Published:

Updated: 2024-09-05T19:54:40.749Z

Reserved: 2023-03-30T09:15:34.398Z

Link: CVE-2023-1714

cve-icon Vulnrichment

Updated: 2024-08-02T05:57:24.932Z

cve-icon NVD

Status : Modified

Published: 2023-11-01T10:15:09.050

Modified: 2024-11-21T07:39:45.173

Link: CVE-2023-1714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.