First published: Thu Aug 24 2017(Updated: )
Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) "by" parameter to admin/orion.extfeedbackform_efbf_forms.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitrix | <=2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8355 has been rated as a critical vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2015-8355, upgrade to the latest version of the orion.extfeedbackform module, specifically version 2.1.3 or higher.
CVE-2015-8355 affects remote authenticated users of Bitrix using the orion.extfeedbackform module prior to version 2.1.3.
The potential impacts of CVE-2015-8355 include unauthorized execution of arbitrary SQL commands, which could lead to data leakage or database compromise.
No reliable workarounds exist for CVE-2015-8355 apart from applying the security update to mitigate the vulnerability.