Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.
Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.
Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.
Vulnerability: CVE-2022-27228
Was this information helpful?
Integration specialist assistance
Get your Bitrix24 set up by local professionals
Don't have an account? Create for free
Related articles
Convert Feed post into a task USB barcode scanner Swap email addresses or phone numbers on your website Connect mailboxes to Bitrix24 Disable automation rules and workflow actions Rent a number Import linked items into CRM Evaluate the REST load in Bitrix24 Bitrix24 e-Signature: Check document integrity Connect PayPal (built-in)