Vulnerability: CVE-2022-27228.
 Publication date: March 21, 2022.
 
 Description:
 Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
 
 Solution:
 Update the "Polls, Votes" (vote) module to 21.0.100 version.
 
 Additional information:
 We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability. 
 
	Vulnerability: CVE-2022-27228
Was this information helpful?
			Integration specialist assistance
				Get your Bitrix24 set up by local professionals
                                
                            
                                
				Don't have an account? Create for free			
		Related articles
																	Edit dashboards in BI Builder									Updated articles: March 2024									Configure call forwarding									Migrate data from other systems to Bitrix24 Inventory management									Old CRM item form is being disabled									Worktime and reports option									Join Bitrix24 via invitation link									Inactive Bitrix24: What's important to know									How a client pays for an order 									Wait for user input in workflows