Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.
Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.
Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.
Vulnerability: CVE-2022-27228

Author: Emily Walker
Last update: March 21, 2022.
Was this information helpful?
Integration specialist assistance
That's not what I'm looking for
Complicated and incomprehensible text
The information is outdated
It's too short. I need more information
I don't like the way this tool works
Related articles
Create customer segments for marketing campaigns Skrill Integration app Login history Access permissions to RPA The "Respect responsible person's working hours" option Accept payment in the deal form in the mobile app Create a stock receipt Instagram Direct: Your account does not meet the terms of connection Tax Information for Bitrix24 products Auto publish and preview options and site navigation Read FAQ
NEW
Bitrix24 Security