The Web Application Firewall in Bitrix24 up to and including 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
id: CVE-2020-13483
info:
name: Bitrix24 <=20.0.0 - Cross-Site Scripting
author: pikpikcu,3th1c_
...