Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via polluting `__proto__[tag]` and `__proto__[text]`.
References
Link | Resource |
---|---|
https://starlabs.sg/advisories/23/23-1717/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: STAR_Labs
Published: 2023-11-01T09:03:46.376Z
Updated: 2023-11-01T09:03:46.376Z
Reserved: 2023-03-30T09:17:02.993Z
Link: CVE-2023-1717
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-11-01T10:15:09.243
Modified: 2023-11-09T20:50:30.427
Link: CVE-2023-1717
JSON object: View
Redhat Information
No data.