Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://starlabs.sg/advisories/23/23-1716/ |
![]() ![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: STAR_Labs
Published: 2023-11-01T09:03:24.512Z
Updated: 2024-09-05T19:52:50.595Z
Reserved: 2023-03-30T09:16:29.698Z
Link: CVE-2023-1716

Updated: 2024-08-02T05:57:25.057Z

Status : Modified
Published: 2023-11-01T10:15:09.183
Modified: 2024-11-21T07:39:45.437
Link: CVE-2023-1716

No data.