Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.
Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.
Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.
Vulnerability: CVE-2022-27228
Was this information helpful?
Integration specialist assistance
Get your Bitrix24 set up by local professionals
Don't have an account? Create for free
Related articles
AI Audio and Video Tasks Manage files in workgroups and projects Change a responsible person Purchase renewals and upgrades for Bitrix24 On-Premise editions Create and send an SMS campaign Change CRM form title, name, and page name Create events in Feed FAQ: Bitrix24 settings Projects in Bitrix24 mobile app Add and customize currencies in CRM