Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23939 | Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://starlabs.sg/advisories/23/23-1716/ |
|
History
No history.
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2024-09-05T19:52:50.595Z
Reserved: 2023-03-30T09:16:29.698Z
Link: CVE-2023-1716
Updated: 2024-08-02T05:57:25.057Z
Status : Modified
Published: 2023-11-01T10:15:09.183
Modified: 2024-11-21T07:39:45.437
Link: CVE-2023-1716
No data.
OpenCVE Enrichment
No data.
EUVD