Перейти к содержимому
Noroxi

Записи Bitrix24

20 опубликованных записей вендора bitrix24.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

20 записей
  • CVE-2022-27228
    45В плане

    In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code

    КритическаяCVSS 9,8Proof of conceptEPSS 21 %

    bitrix24 · bitrix2422 мар. 2022 г.

  • CVE-2023-1719
    40В плане

    Bitrix24 Insecure Global Variable Extraction

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2020-13484
    40В плане

    Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    bitrix24 · bitrix2424 июн. 2020 г.

  • CVE-2023-1717
    38Наблюдать

    Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2023-1716
    38Наблюдать

    Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (2 of 2)

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2023-1718
    37Наблюдать

    Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access

    ВысокаяCVSS 7,5Proof of conceptEPSS 24 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2023-1714
    35Наблюдать

    Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2023-1713
    35Наблюдать

    Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2023-1720
    32Наблюдать

    Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2024-34885
    27Наблюдать

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP acco

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    bitrix24 · bitrix244 нояб. 2024 г.

  • CVE-2024-34891
    27Наблюдать

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange a

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    bitrix24 · bitrix244 нояб. 2024 г.

  • CVE-2020-28206
    26Наблюдать

    An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bitrix24 · bitrix framework2 дек. 2020 г.

  • CVE-2020-13483
    25Наблюдать

    The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.lis

    СредняяCVSS 6,1Proof of conceptEPSS 5 %

    bitrix24 · bitrix2424 июн. 2020 г.

  • CVE-2008-2052
    24Наблюдать

    Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    bitrix24 · bitrix site manager2 мая 2008 г.

  • CVE-2023-1715
    21Наблюдать

    Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (1 of 2)

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2017-20122
    21Наблюдать

    Bitrix Site Manager Contact Form cross site scripting

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    bitrix24 · bitrix site manager30 июн. 2022 г.

  • CVE-2022-43959
    19Наблюдать

    Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to

    СредняяCVSS 4,9Proof of conceptEPSS 1 %

    bitrix24 · bitrix2420 янв. 2023 г.

  • CVE-2024-34883
    19Наблюдать

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-serve

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    bitrix24 · bitrix244 нояб. 2024 г.

  • CVE-2024-34882
    19Наблюдать

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP acco

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    bitrix24 · bitrix244 нояб. 2024 г.

  • CVE-2024-34887
    19Наблюдать

    Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDA

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    bitrix24 · bitrix244 нояб. 2024 г.