CVE-2023-1719 affects Bitrix24 22.0.300 and is caused by unsafe global variable extraction in bitrix/modules/main/tools.php. During request initialization, the FormDecode function copies attacker-controlled values from request-related sources such as GET, POST, and Cookie data into $GLOBALS when keys are not denylisted and the target variables are not already initialized. Because this occurs early in application startup, uninitialized variables later consumed by application logic can become attacker-controlled. The issue was demonstrated in two reachable paths. First, in /pub/im.file.php, the variables $diskFileId and $sign may remain uninitialized unless specific request parameters are set; an attacker can overwrite them through global extraction and reach file access logic that compares the two values and retrieves a Bitrix Disk file, enabling unauthenticated attachment enumeration and access. Second, in /bitrix/components/bitrix/socialnetwork.events_dyn/get_message_2.php, the $log_cnt variable may remain uninitialized for unauthenticated requests and is later reflected through CUtil::PhpToJSObject, enabling reflected XSS. The report further states that Bitrix24's sanitizer can be bypassed using the Unicode paragraph separator U+2029, which is transformed into a regular space by CUtil::JSEscape, allowing construction of a valid event-handler payload.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Bitrix cross-site scripting vulnerability mentioned in passing as another template that may benefit from stronger fingerprint checks. No further details are provided.
A high-severity Bitrix24 vulnerability caused by global variable extraction in tools.php that lets unauthenticated attackers overwrite uninitialized variables, enabling attachment enumeration/IDOR and reflected XSS, with possible server-side code execution if an administrator is targeted.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.