References https://stack.chaitin.com/poc/detail/3455 https://www.ctfiot.com/125546.html https://www.redpacketsecurity.com/bitrix-restore-php-file-upload-cve-2022-29268/ https://hackyourmom.com/en/kibervijna/bitrix-pid-atakoyu-krytychni-vrazlyvosti-eksplojty-ta-kontrol-nad-systemoyu-chastyna-2/ https://onelab.kz/en/articles/project-management/review-of-weak-points-in-1c-bitrix-and-ways-to-eliminate-them/
Related VulnerabilitiesPoCCVE-2008-2052: Bitrix Site Manager 6.5 - Open RedirectPoCCVE-2022-38130: KeySight RF - smsRestoreDatabaseZip UNC path to Remote Code ExecutionPoCbitrix-fpd: Bitrix Path DisclosurePoCbitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure智联云采 SRM2.0 /adpweb/static/..;/a/db/dbBackupScheme/restore 命令执行漏洞SRM智联云采系统 restore 远程代码执行漏洞智联云采 SRM2.0 restore 存在远程命令执行漏洞索贝融媒体 /sobey-mchEditor/mch/WXArticleInt/restore SQL注入漏洞Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518)PoCCVE-2020-13483: Bitrix24 <=20.0.0 - Cross-Site ScriptingPoCCVE-2023-1719: Bitrix Component - Cross-Site Scripting