CVE-2023-1713
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 1, 2023
Updated: Nov 9, 2023
CWE ID 434
Summary
CVE-2023-1713 is a vulnerability affecting Bitrix24 22.0.300's crm module, specifically in the instagram.php file located in the order/import directory. This issue arises due to insecure temporary file creation. A remote authenticated attacker can exploit this flaw by uploading a specially crafted .htaccess file, allowing them to execute arbitrary code on the Apache HTTP Server hosting the Bitrix24 application. This vulnerability poses a significant risk to the security of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Bitrix24
Affected Vendors
- Bitrix24