A logic error when using mb_strpos()... CVE-2023-1715

- AV AC AU C I A
发布: 2023-11-01
修订: 2023-11-08

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息