CVE-2023-1714
HIGHBitrix24 <22.0.300 - Authenticated RCE
Title source: llmDescription
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Scores
CVSS v3
8.8
EPSS
0.0244
EPSS Percentile
85.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
bitrix24/bitrix24
Timeline
Published
Nov 01, 2023
Tracked Since
Feb 18, 2026