First published: Wed Nov 01 2023(Updated: )
Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Receiver | =22.0.300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1713 is a vulnerability in Bitrix24 that allows remote authenticated attackers to execute arbitrary code through insecure temporary file creation.
CVE-2023-1713 has a severity rating of 8.8 (high).
CVE-2023-1713 works by exploiting insecure temporary file creation in the 'instagram.php' file of Bitrix24, which allows remote authenticated attackers to upload a crafted '.htaccess' file and execute arbitrary code.
To fix CVE-2023-1713, update your Bitrix24 installation to version 22.0.300 or apply the necessary patches provided by Bitrix24.
You can find more information about CVE-2023-1713 at this [link](https://starlabs.sg/advisories/23/23-1713/).