S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-1719 Scanner

CVE-2023-1719 scanner - Cross-Site Scripting vulnerability in Bitrix24

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-1719
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Bitrix24by Bitrix24
0
Updated Aug 22, 2026View on NVD →
Detail

Bitrix24 is a comprehensive collaboration platform offering a wide range of business management and communication tools. It integrates CRM, project management, contact center, website builder, and HR system functionalities, catering to the diverse needs of businesses aiming to streamline operations and enhance productivity. This platform is widely used by companies worldwide to manage sales, communication, tasks, and projects in a centralized manner. The software is crucial for organizations looking to improve collaboration, customer engagement, and overall operational efficiency. The vulnerability affects version 22.0.300, highlighting the need for rigorous security practices in web-based applications.

CVE-2023-1719 represents a critical vulnerability in Bitrix24 version 22.0.300, where global variable extraction mechanisms can be exploited by unauthenticated attackers. This flaw allows attackers to enumerate server attachments and execute arbitrary JavaScript code within victims' browsers. Furthermore, if the victim has administrative privileges, it could potentially lead to arbitrary PHP code execution on the server. The exploitation of this vulnerability underscores the significant risks associated with improper input validation and variable handling.

The issue stems from the improper handling of global variables in the bitrix/modules/main/tools.php file, specifically within the socialnetwork.events_dyn/get_message_2.php component. By manipulating the log_cnt parameter, attackers can inject malicious scripts that are executed when the page is rendered in a user's browser. This attack vector not only compromises the integrity of the session but also poses a risk of further escalation, depending on the privileges of the session compromised. This highlights the critical importance of sanitizing input to prevent unauthorized actions on the platform.

Successful exploitation of this XSS vulnerability can lead to data theft, unauthorized access to user sessions, modification of displayed content, and potentially server-side code execution. The ability to run arbitrary scripts in the context of the user's session can compromise the security and privacy of user data, undermine the trust in the application, and cause significant reputational damage to the organization using Bitrix24.

By leveraging the S4E (S4E) platform, organizations can identify vulnerabilities like CVE-2023-1719 within their digital infrastructure. S4E's comprehensive scanning capabilities provide in-depth analysis and actionable insights to mitigate potential threats effectively. Membership with S4E ensures continuous monitoring and expert guidance, enhancing your cybersecurity posture and safeguarding your operations against evolving digital threats. Join S4E today to protect your assets and maintain the trust of your customers and stakeholders.

 

References

Solution Advice
  1. Update Bitrix24 to the latest version that addresses this vulnerability, ensuring that your system is not running version 22.0.300 or any other vulnerable versions.
  2. Implement input validation and sanitization measures to prevent the injection of malicious code through user inputs.
  3. Regularly review and update security policies and practices to address new and emerging threats.
  4. Educate users about the importance of secure browsing practices to reduce the risk of exploitation through social engineering attacks.
  5. Monitor and analyze application logs for unusual activities that may indicate attempts to exploit vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.