CVE-2022-27228: Input Validation
Published Mar 22, 2022
·Updated
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
Affected Software
1 affected component
Bitrix24 Bitrix24<21.0.100
Event History
Mar 22, 2022
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Bitrix Site Manager vulnerability?
The vulnerability ID is CVE-2022-27228.
2
What is the severity level of CVE-2022-27228?
The severity level of CVE-2022-27228 is critical.
3
How can an attacker exploit CVE-2022-27228?
An attacker can exploit CVE-2022-27228 by executing arbitrary code remotely.
4
Which version of Bitrix Site Manager is affected by CVE-2022-27228?
Bitrix Site Manager version up to 21.0.100 is affected by CVE-2022-27228.
5
Is authentication required to exploit CVE-2022-27228?
No, authentication is not required to exploit CVE-2022-27228.