CVE-2023-1717 | Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution
Exp
Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via polluting `__proto__[tag]` and `__proto__[text]`.
Conclusion & alert: CVE-2023-1717 is rated High Exploit Risk (73.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.05%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2023-1717
Exploit prediction scoring system (EPSS) score for CVE-2023-1717
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).