Security Advisory

CVE-2023-1715

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-11-01 09:03:05
Last updated 2024-09-05 19:53:48
Assigner STAR_Labs
CVSS score 9.0
State PUBLISHED

Description

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.