Vulnerability: CVE-2022-27228.
Publication date: March 21, 2022.
Description:
Insufficient validation of user input allows a remote unauthenticated attacker to execute arbitrary code on a system. It can result in gaining control of the target system.
Solution:
Update the "Polls, Votes" (vote) module to 21.0.100 version.
Additional information:
We express our gratitude to Sergey Bliznyuk (Positive Technologies) for his help in finding the vulnerability.
Vulnerability: CVE-2022-27228
Was this information helpful?
Integration specialist assistance
Get your Bitrix24 set up by local professionals
Don't have an account? Create for free
Related articles
Create a task Open slots in Bitrix24 calendar Work with collab tasks Bitrix24 e-Signature for HR: service for signing HR documents FAQ: Company and employees Time and reports Check task upon completion Personalize activity reminders in CRM Role-based access permissions in CRM Print Inventory management documents