CVE-2023-1713

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
01/11/2023
Last modified:
09/11/2023

Description

Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitrix24:bitrix24:22.0.300:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools