Bitrix Component 漏洞列表
共找到 2 个与 Bitrix Component 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2023-1719: Bitrix Component - Cross-Site Scripting POC
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables. -
CVE-2023-1719: Bitrix Component - Cross-Site Scripting POC
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.