Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.
Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.
Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.
Vulnerability: CVE-2022-27228
Was this information helpful?
Integration specialist assistance
Get your Bitrix24 set up by local professionals
Don't have an account? Create for free
Related articles
Add a new workflow field Number of users on Bitrix24 Cloud plans Tasks in collabs Make a field required in a CRM form Activities: Element Processing FAQ: Security Bitrix24: what's new in July 2024 View email headers (RFC headers) Quick task creation form Billable Hours For Tasks app