CVE-2015-8355: SQL Injection
Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) "by" parameter to admin/orion.extfeedbackformefbfforms.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8355?
CVE-2015-8355 has been rated as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2015-8355?
To fix CVE-2015-8355, upgrade to the latest version of the orion.extfeedbackform module, specifically version 2.1.3 or higher.
Who is affected by CVE-2015-8355?
CVE-2015-8355 affects remote authenticated users of Bitrix using the orion.extfeedbackform module prior to version 2.1.3.
What are the potential impacts of CVE-2015-8355?
The potential impacts of CVE-2015-8355 include unauthorized execution of arbitrary SQL commands, which could lead to data leakage or database compromise.
Are there any workarounds for CVE-2015-8355?
No reliable workarounds exist for CVE-2015-8355 apart from applying the security update to mitigate the vulnerability.