CVE-2023-1718 | Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access
Exp
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".
Conclusion & alert: CVE-2023-1718 is rated High Exploit Risk (80.7/100): CVSS High severity, with high exploitation likelihood (EPSS 51.15%, 98th percentile).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.48% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2023-1718
Exploit prediction scoring system (EPSS) score for CVE-2023-1718
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).