Записи Bitrix24
20 опубликованных записей вендора bitrix24.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-522 Insufficiently Protected Credentials4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-502 Deserialization of Untrusted Data1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2022-27228Proof of concept | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary codebitrix24 · bitrix24 · CWE-20 | Критическая9,8 | — | 20,8 % | 22 мар. 2022 г. |
40В плане | CVE-2023-1719Proof of concept | Bitrix24 Insecure Global Variable Extractionbitrix24 · bitrix24 · CWE-665 | Критическая9,8 | — | 5,0 % | 1 нояб. 2023 г. |
40В плане | CVE-2020-13484Эксплойта нет | Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if thebitrix24 · bitrix24 · CWE-918 | Критическая9,8 | — | 2,0 % | 24 июн. 2020 г. |
38Наблюдать | CVE-2023-1717Эксплойта нет | Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollutionbitrix24 · bitrix24 · CWE-79 | Критическая9,6 | — | 1,1 % | 1 нояб. 2023 г. |
38Наблюдать | CVE-2023-1716Эксплойта нет | Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (2 of 2)bitrix24 · bitrix24 · CWE-79 | Критическая9,6 | — | 0,7 % | 1 нояб. 2023 г. |
37Наблюдать | CVE-2023-1718Proof of concept | Bitrix24 Denial-of-Service (DoS) via Improper File Stream Accessbitrix24 · bitrix24 · CWE-835 | Высокая7,5 | — | 24,1 % | 1 нояб. 2023 г. |
35Наблюдать | CVE-2023-1714Эксплойта нет | Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extractionbitrix24 · bitrix24 · CWE-502 | Высокая8,8 | — | 1,4 % | 1 нояб. 2023 г. |
35Наблюдать | CVE-2023-1713Эксплойта нет | Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creationbitrix24 · bitrix24 · CWE-434 | Высокая8,8 | — | 1,2 % | 1 нояб. 2023 г. |
32Наблюдать | CVE-2023-1720Эксплойта нет | Bitrix24 Stored Cross-Site Scripting (XSS) via File Uploadbitrix24 · bitrix24 · CWE-434 | Высокая8,0 | — | 0,9 % | 1 нояб. 2023 г. |
27Наблюдать | CVE-2024-34885Эксплойта нет | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accobitrix24 · bitrix24 · CWE-522 | Средняя6,8 | — | 0,4 % | 4 нояб. 2024 г. |
27Наблюдать | CVE-2024-34891Эксплойта нет | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange abitrix24 · bitrix24 · CWE-312 | Средняя6,8 | — | 0,3 % | 4 нояб. 2024 г. |
26Наблюдать | CVE-2020-28206Эксплойта нет | An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0.bitrix24 · bitrix framework · CWE-307 | Средняя6,5 | — | 1,1 % | 2 дек. 2020 г. |
25Наблюдать | CVE-2020-13483Proof of concept | The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.lisbitrix24 · bitrix24 · CWE-79 | Средняя6,1 | — | 4,5 % | 24 июн. 2020 г. |
24Наблюдать | CVE-2008-2052Proof of concept | Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and bitrix24 · bitrix site manager · CWE-601 | Средняя6,1 | — | 1,6 % | 2 мая 2008 г. |
21Наблюдать | CVE-2023-1715Эксплойта нет | Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (1 of 2)bitrix24 · bitrix24 · CWE-79 | Средняя5,4 | — | 0,6 % | 1 нояб. 2023 г. |
21Наблюдать | CVE-2017-20122Эксплойта нет | Bitrix Site Manager Contact Form cross site scriptingbitrix24 · bitrix site manager · CWE-80 | Средняя5,4 | — | 0,5 % | 30 июн. 2022 г. |
19Наблюдать | CVE-2022-43959Proof of concept | Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to bitrix24 · bitrix24 · CWE-200 | Средняя4,9 | — | 1,0 % | 20 янв. 2023 г. |
19Наблюдать | CVE-2024-34883Эксплойта нет | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-servebitrix24 · bitrix24 · CWE-522 | Средняя4,9 | — | 0,4 % | 4 нояб. 2024 г. |
19Наблюдать | CVE-2024-34882Эксплойта нет | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP accobitrix24 · bitrix24 · CWE-522 | Средняя4,9 | — | 0,3 % | 4 нояб. 2024 г. |
19Наблюдать | CVE-2024-34887Эксплойта нет | Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAbitrix24 · bitrix24 · CWE-522 | Средняя4,9 | — | 0,3 % | 4 нояб. 2024 г. |
- CVE-2022-2722845В плане
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code
КритическаяCVSS 9,8Proof of conceptEPSS 21 %bitrix24 · bitrix2422 мар. 2022 г.
- CVE-2023-171940В плане
Bitrix24 Insecure Global Variable Extraction
КритическаяCVSS 9,8Proof of conceptEPSS 5 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2020-1348440В плане
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bitrix24 · bitrix2424 июн. 2020 г.
- CVE-2023-171738Наблюдать
Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2023-171638Наблюдать
Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (2 of 2)
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2023-171837Наблюдать
Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
ВысокаяCVSS 7,5Proof of conceptEPSS 24 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2023-171435Наблюдать
Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2023-171335Наблюдать
Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2023-172032Наблюдать
Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2024-3488527Наблюдать
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP acco
СредняяCVSS 6,8Эксплойта нетEPSS 0 %bitrix24 · bitrix244 нояб. 2024 г.
- CVE-2024-3489127Наблюдать
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange a
СредняяCVSS 6,8Эксплойта нетEPSS 0 %bitrix24 · bitrix244 нояб. 2024 г.
- CVE-2020-2820626Наблюдать
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bitrix24 · bitrix framework2 дек. 2020 г.
- CVE-2020-1348325Наблюдать
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.lis
СредняяCVSS 6,1Proof of conceptEPSS 5 %bitrix24 · bitrix2424 июн. 2020 г.
- CVE-2008-205224Наблюдать
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and
СредняяCVSS 6,1Proof of conceptEPSS 2 %bitrix24 · bitrix site manager2 мая 2008 г.
- CVE-2023-171521Наблюдать
Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (1 of 2)
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2017-2012221Наблюдать
Bitrix Site Manager Contact Form cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bitrix24 · bitrix site manager30 июн. 2022 г.
- CVE-2022-4395919Наблюдать
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to
СредняяCVSS 4,9Proof of conceptEPSS 1 %bitrix24 · bitrix2420 янв. 2023 г.
- CVE-2024-3488319Наблюдать
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-serve
СредняяCVSS 4,9Эксплойта нетEPSS 0 %bitrix24 · bitrix244 нояб. 2024 г.
- CVE-2024-3488219Наблюдать
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP acco
СредняяCVSS 4,9Эксплойта нетEPSS 0 %bitrix24 · bitrix244 нояб. 2024 г.
- CVE-2024-3488719Наблюдать
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDA
СредняяCVSS 4,9Эксплойта нетEPSS 0 %bitrix24 · bitrix244 нояб. 2024 г.