CVE-2022-43959EPSS p58.7%
CVE-2022-43959CVE-2022-43959
bitrix24 / bitrix24
Description
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.
Scoring
| CVSS | 4.9 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 1.01% probability of exploitation · percentile 58.7% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |