Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-1714

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 86.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-1714
  • Bitrix24 » Bitrix24 » Version: 22.0.300
    cpe:2.3:a:bitrix24:bitrix24:22.0.300


Contact Us

Shodan ® - All rights reserved