First published: Fri Jan 20 2023(Updated: )
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Receiver | <=22.200.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43959 is medium with a CVSS score of 4.9.
Remote administrators can discover the AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php in 1C-Bitrix Bitrix24 version up to 22.200.200.
To fix CVE-2022-43959, upgrade to a version of 1C-Bitrix Bitrix24 equal to or above 22.200.200.
For more information about CVE-2022-43959, you can visit the following references: [GitHub](https://github.com/secware-ru/CVE-2022-43959), [Bitrix24 Pricing](https://www.bitrix24.com/prices/self-hosted.php), [Bitrix24 Security](https://www.bitrix24.com/security/).