Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://starlabs.sg/advisories/23/23-1719/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: STAR_Labs
Published: 2023-11-01T09:04:19.695Z
Updated: 2024-09-05T19:43:24.735Z
Reserved: 2023-03-30T09:19:45.104Z
Link: CVE-2023-1719
Vulnrichment
Updated: 2024-08-02T05:57:25.191Z
NVD
Status : Modified
Published: 2023-11-01T10:15:09.373
Modified: 2024-11-21T07:39:45.817
Link: CVE-2023-1719
Redhat
No data.