CVE-2023-1713: BITRIX24

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.

Affected products

  • BITRIX24 BITRIX24: version 22.0.300 only

Published 2023-11-01. Last modified 2026-06-17.