CVE-2020-13483: XSS
Published Jun 24, 2020
·Updated
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
Affected Software
1 affected component
Bitrix24 Bitrix24<=20.0.0
Event History
Jun 24, 2020
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
Description
Frequently Asked Questions
1
What is CVE-2020-13483?
CVE-2020-13483 is a vulnerability in the Web Application Firewall in Bitrix24 through 20.0.0 that allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
2
What is the severity of CVE-2020-13483?
The severity of CVE-2020-13483 is medium with a CVSS score of 6.1.
3
How does CVE-2020-13483 affect Bitrix24?
CVE-2020-13483 affects Bitrix24 versions up to and including 20.0.0.
4
How can I fix CVE-2020-13483?
To fix CVE-2020-13483, it is recommended to update Bitrix24 to a version beyond 20.0.0.
5
Where can I find more information about CVE-2020-13483?
You can find more information about CVE-2020-13483 at the following reference: https://gist.github.com/mariuszpoplwski/ca6258cf00c723184ebd2228ba81f558