Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://starlabs.sg/advisories/23/23-1719/ |
![]() ![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2024-09-05T19:43:24.735Z
Reserved: 2023-03-30T09:19:45.104Z
Link: CVE-2023-1719

Updated: 2024-08-02T05:57:25.191Z

Status : Modified
Published: 2023-11-01T10:15:09.373
Modified: 2024-11-21T07:39:45.817
Link: CVE-2023-1719

No data.