CVE-2023-1714: BITRIX24
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.
Affected products
- BITRIX24 BITRIX24: version 22.0.300 only
Published 2023-11-01. Last modified 2026-06-17.