CVE-2023-1720

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
01/11/2023
Last modified:
09/11/2023

Description

Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitrix24:bitrix24:22.0.300:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools