Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-1715

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.3%
CVSS Severity
CVSS v3 Score 9.0
Products affected by CVE-2023-1715
  • Bitrix24 » Bitrix24 » Version: 22.0.300
    cpe:2.3:a:bitrix24:bitrix24:22.0.300


Contact Us

Shodan ® - All rights reserved