First published: Wed Nov 01 2023(Updated: )
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Receiver | =22.0.300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1718 is a vulnerability in Bitrix24 that allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url."
CVE-2023-1718 has a severity level of 7.5 (high).
CVE-2023-1718 affects Bitrix24 versions 22.0.300.
To fix CVE-2023-1718, update Bitrix24 to a version that is not affected.
You can find more information about CVE-2023-1718 at the following link: [https://starlabs.sg/advisories/23/23-1718/]