CVE-2020-28206

MEDIUM

Bitrix Framework 20.0 - User Enumeration & Authentication Brute-Force in Admin Login

Title source: llm
STIX 2.1

Description

An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0113
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-307
Status published
Products (1)
bitrix24/bitrix_framework 20.0
Published Dec 02, 2020
Tracked Since Feb 18, 2026