CVE-2024-34887
EUVD-2024-3510204.11.2024, 18:15
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bitrix24 | bitrix24 | 23.300.100 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| bitrix | bitrix24 | 23.300.100 | ADP |
Common Weakness Enumeration