CVE-2023-1713: BITRIX24
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.
Affected products
- BITRIX24 BITRIX24: version 22.0.300 only
Published 2023-11-01. Last modified 2026-06-17.