CVE-2020-13483: BITRIX24
Medium severity, CVSS 6.1. EPSS: 4.5% chance of exploitation in the next 30 days.
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
Affected products
- BITRIX24 BITRIX24: up to and including 20.0.0
Published 2020-06-24. Last modified 2026-06-17.