Description
Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23936 | Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file. |
References
| Link | Providers |
|---|---|
| https://starlabs.sg/advisories/23/23-1713/ |
|
History
No history.
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2024-09-05T19:55:42.789Z
Reserved: 2023-03-30T09:14:16.052Z
Link: CVE-2023-1713
Updated: 2024-08-02T05:57:24.863Z
Status : Modified
Published: 2023-11-01T10:15:08.973
Modified: 2024-11-21T07:39:45.037
Link: CVE-2023-1713
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD