CVE-2023-1714: BITRIX24

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.

Affected products

  • BITRIX24 BITRIX24: version 22.0.300 only

Published 2023-11-01. Last modified 2026-06-17.