Vulnerabilities
Vulnerable Software
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.
CVSS Score
6.8
EPSS Score
0.002
Published
2024-11-04
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.
CVSS Score
6.8
EPSS Score
0.001
Published
2024-11-04
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.
CVSS Score
4.9
EPSS Score
0.001
Published
2024-11-04
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.
CVSS Score
4.9
EPSS Score
0.001
Published
2024-11-04
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.
CVSS Score
4.9
EPSS Score
0.001
Published
2024-11-04


Contact Us

Shodan ® - All rights reserved