Vulnerabilities > CVE-2023-1718 - Infinite Loop vulnerability in Bitrix24 22.0.300
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |