CVE-2023-1718: Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
Published Nov 1, 2023
·Updated
Improper file stream access in /desktopapp/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmpurl".
Affected Software
1 affected component
Bitrix24 Bitrix24=22.0.300
Event History
Nov 1, 2023
CVE Published
09:04 AM
Data Sourced
09:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-1718?
CVE-2023-1718 is a vulnerability in Bitrix24 that allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url."
2
What is the severity of CVE-2023-1718?
CVE-2023-1718 has a severity level of 7.5 (high).
3
How does CVE-2023-1718 affect Bitrix24?
CVE-2023-1718 affects Bitrix24 versions 22.0.300.
4
How can I fix CVE-2023-1718?
To fix CVE-2023-1718, update Bitrix24 to a version that is not affected.
5
Where can I find more information about CVE-2023-1718?
You can find more information about CVE-2023-1718 at the following link: [https://starlabs.sg/advisories/23/23-1718/]