CVE-2023-1720
📛 CVE Title
Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload
Description
Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- STAR_Labs
- CVSS severity
- CRITICAL
- CVSS score
- 9.6 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H- Effective score
- 9.6 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-434 - Reserved
- 2023-03-30
- Published
- 2023-11-01 10:04 UTC
- Last updated
- 2024-09-05 21:41 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/1xxx/CVE-2023-1720.json
- Linked Threat
- CVE-2023-1720 — Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2023-11-01 10:15:09 UTC
- NVD last modified
- 2026-06-17 05:28:36 UTC
- NVD CVSS v3.1
- 9.6 / 10 CRITICAL source: info@starlabs.sg
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 6.0 / 10
- EPSS score
- 0.0085 (probability of exploitation in next 30 days)
- EPSS percentile
- 53.50% vs all CVEs — higher = more likely to be exploited, as of 2026-06-25
NVD / KEV / EPSS data refreshed 2026-06-26 05:24 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-23943 - Assigner
- STAR_Labs
- Published
- Nov 1, 2023, 9:04:46 AM
- Updated
- Sep 5, 2024, 7:41:48 PM
- EUVD base score (CVSS 3.1)
-
9.6 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - EUVD-reported EPSS
- 1.0200
- Vendors
- Bitrix24
- Products
-
Bitrix24 (0 ≤22.0.300)
- Aliases
-
GHSA-3f75-53r3-6ghw
ENISA description: Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Bitrix24 | Bitrix24 |
0 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:bitrix24:bitrix24:22.0.300:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://starlabs.sg/advisories/23/23-1720/ third-party-advisory
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- https://starlabs.sg/advisories/23/23-1720/ third-party-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://starlabs.sg/advisories/23/23-1720/ info@starlabs.sg ExploitThird Party Advisory
- https://starlabs.sg/advisories/23/23-1720/ af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party Advisory
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
file.ajax.php
|
no local data | 2026-05-18 21:20 UTC |
Remediations (17)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.facebook.com
Here is an update to the missing person search from Thursday (link in the comments) Kathy Kimball Dykeman and 23 others 24 9 Concord NH Patch 1d Porch chats, block parties and back-and-forth favors once defined neighborhood life. Now, even small connections feel harder to find. PATCH .COM What Happened To The ...
2026-06-03 01:29 UTC -
web:arcraiders.com
ARC Raiders is a multiplayer extraction adventure, set in a lethal future earth, ravaged by a mysterious mechanized threat known as ARC.
2026-06-03 01:29 UTC -
web:blog.qualys.com
RedSun is a zero-day LPE in Microsoft Defender with no patch available. Learn how to detect and mitigate it instantly using Qualys VMDR and TruRisk™ Eliminate.
2026-06-03 01:29 UTC -
web:app.opencve.io
Explore the latest vulnerabilities and security issues in the CVE database
2026-06-03 01:29 UTC -
web:www.pockettactics.com
Grab these new Fix It Up codes to redeem plenty of free euros and build up your dream garage in this fun Roblox mechanic simulator.
2026-06-03 01:29 UTC -
web:nvd.nist.gov
Mitigation of the vulnerabilities in this context typically involves coding changes, but could also include specification changes or even specification deprecations (e.g., removal of affected protocols or functionality in their entirety)."
2026-06-03 01:29 UTC -
web:x.com
Attention, Helldivers! Due to an unexpected submission bug outside of our control, today's patch will be slightly delayed. We're working to confirm an updated release time, but this depends on our platform partners, who are actively investigating and resolving the issue. We will share more information as soon as a new release time is confirmed. In the meantime, we are sharing the expanded ...
2026-06-03 01:29 UTC -
web:www.linkedin.com
Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...
2026-05-22 05:40 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 05:40 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 05:40 UTC -
web:www.cisa.gov
For patch information on CVEs identified in this advisory, refer to the Appendix: Patch Information and Additional Resources for Top Exploited Vulnerabilities. If a patch for a KEV or critical vulnerability cannot be quickly applied, implement vendor-approved workarounds.
2026-05-22 05:40 UTC -
web:documentation.n-able.com
For more information on how Patch Manager provides third-party patching, see Patching third-party software. Use the table's InstallerURLs location when configuring vendor and patch exclusions in your firewalls and other web-monitoring software.
2026-05-22 05:40 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:40 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:40 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-05-22 05:40 UTC -
web:www.cybersecuritydive.com
The Cybersecurity and Infrastructure Security Agency added two major software flaws to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, acknowledging the evidence that hackers have been using the bugs in recent attacks. CISA added CVE -2024-1708, a high-severity flaw in ConnectWise's ScreenConnect remote-access tool, and CVE -2026-32202, a medium-severity flaw in the Windows Shell ...
2026-05-22 05:40 UTC -
web:www.forbes.com
Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.
2026-05-22 05:40 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-1720.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:57:24.889Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"third-party-advisory",
"x_transferred"
],
"url": "https://starlabs.sg/advisories/23/23-1720/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-1720",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-05T19:41:37.003461Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-05T19:41:48.166Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Bitrix24",
"programFiles": [
"file:desktop_app/file.ajax.php"
],
"vendor": "Bitrix24",
"versions": [
{
"lessThanOrEqual": "22.0.300",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Lam Jun Rong & Li Jiantao of STAR Labs SG Pte. Ltd. (@starlabs_sg)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile."
}
],
"value": "Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile."
}
],
"impacts": [
{
"capecId": "CAPEC-592",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-592 Stored XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-11-01T09:04:46.293Z",
"orgId": "b1571b85-cbc9-431f-830b-0c8155323a69",
"shortName": "STAR_Labs"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://starlabs.sg/advisories/23/23-1720/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "b1571b85-cbc9-431f-830b-0c8155323a69",
"assignerShortName": "STAR_Labs",
"cveId": "CVE-2023-1720",
"datePublished": "2023-11-01T09:04:46.293Z",
"dateReserved": "2023-03-30T09:19:46.683Z",
"dateUpdated": "2024-09-05T19:41:48.166Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}