CVE-2023-1718: BITRIX24
High severity, CVSS 7.5. EPSS: 24.1% chance of exploitation in the next 30 days.
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
Affected products
- BITRIX24 BITRIX24: version 22.0.300 only
Published 2023-11-01. Last modified 2026-06-17.