← Back to CVE List

CVE-2020-13484

Published: 2020-06-24T15:15Z
Last Modified: 2024-11-21T05:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt