CVE-2023-1715
A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags…
A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags…
Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute…
Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code…
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service…
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service…
In camera driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service…
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution…
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution…
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution…
In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local denial of service with no additional…