Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-1716

Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.7%
CVSS Severity
CVSS v3 Score 9.0
Products affected by CVE-2023-1716
  • Bitrix24 » Bitrix24 » Version: 22.0.300
    cpe:2.3:a:bitrix24:bitrix24:22.0.300


Contact Us

Shodan ® - All rights reserved