First published: Wed Jun 24 2020(Updated: )
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Receiver | <=20.0.975 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13484 is a vulnerability in Bitrix24 that allows server-side request forgery (SSRF) via an intranet IP address.
CVE-2020-13484 has a severity rating of 9.8 out of 10, which is classified as critical.
CVE-2020-13484 allows an attacker to perform SSRF attacks by using an intranet IP address in the URL parameter 'action=attachUrlPreview', if the destination URL contains specific HTML content.
Bitrix24 versions up to and including 20.0.975 are affected by CVE-2020-13484.
At the moment, there is no official fix available for CVE-2020-13484. It is recommended to follow the provided references for any updates or patches.