Bitrix24Care

Vulnerability: CVE-2022-27228

Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.

Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.

Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.

Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.

Was this information helpful?
Integration specialist assistance
That's not what I'm looking for
Complicated and incomprehensible text
The information is outdated
It's too short. I need more information
I don't like the way this tool works
Go to Bitrix24
Don't have an account? Create for free
Related articles
HR bot in Bitrix24 e-Signature for HR Updated articles: July 2022 Configure numbers Lock documents while editing Search and filter messages in Feed CRM: Other settings Payments for Bitrix24 Telephony Configure access permissions to widgets Synchronize Bitrix24 calendar with Microsoft Outlook Place CRM form on site created not in Bitrix24