CVE-2023-1714

HIGH

Bitrix24 <22.0.300 - Authenticated RCE

Title source: llm

Description

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.

Scores

CVSS v3 8.8
EPSS 0.0244
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

bitrix24/bitrix24

Timeline

Published Nov 01, 2023
Tracked Since Feb 18, 2026