CVE-2024-34887
04.11.2024, 18:15
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.Enginsight
Vendor | Product | Version |
---|---|---|
bitrix24 | bitrix24 | 23.300.100 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration