CVE-2023-1718: BITRIX24

High severity, CVSS 7.5. EPSS: 24.1% chance of exploitation in the next 30 days.

Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".

Affected products

  • BITRIX24 BITRIX24: version 22.0.300 only

Published 2023-11-01. Last modified 2026-06-17.