CVE Vulnerabilities

CVE-2023-1718

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Nov 01, 2023 | Modified: Nov 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted tmp_url.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Bitrix24 Bitrix24 22.0.300 (including) 22.0.300 (including)

References