CVE-2020-13483 — exposed on the internet
Internet exposure observed by OffSeq scans · last 30 days
34
Exposed hosts
6.1
CVSS
4.5%
EPSS
Found on 34 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.
About CVE-2020-13483
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
CWE-79
OffSeq internet scanning found CVE-2020-13483 on 34 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.
Open the live CVE-2020-13483 view →