CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.0. See the original NVD description below for full technical details.
CVE
CVE-2023-1715
Severity
CRITICAL
CVSS
9
EPSS
0.59%
Original NVD Description
A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.
Related CVEs
Other vulnerabilities affecting the same vendor(s)