CVE-2023-1716: Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (2 of 2)
Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1716?
CVE-2023-1716 is a cross-site scripting (XSS) vulnerability in the Invoice Edit Page of Bitrix24 22.0.300.
How does CVE-2023-1716 affect Bitrix24?
CVE-2023-1716 allows attackers to execute arbitrary JavaScript code in the victim's browser and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.
What is the severity of CVE-2023-1716?
CVE-2023-1716 has a severity rating of 9, which is considered critical.
How can I fix CVE-2023-1716 in Bitrix24?
To fix CVE-2023-1716, it is recommended to update Bitrix24 to version 22.0.301 or later.
Where can I find more information about CVE-2023-1716?
You can find more information about CVE-2023-1716 on the Star Labs advisory page: https://starlabs.sg/advisories/23/23-1716/