CVE-2025-67886: Malicious File Upload
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67886?
CVE-2025-67886 has a medium severity rating of 6.3 according to CVSS 3.1.
How can CVE-2025-67886 be exploited?
CVE-2025-67886 can be exploited by an attacker with SOURCE/WRITE permissions for the Translate Module who uploads and executes malicious PHP files.
What is the potential impact of CVE-2025-67886?
The potential impact of CVE-2025-67886 includes remote code execution, which could lead to unauthorized control of the affected Bitrix24 system.
How do I fix CVE-2025-67886?
To mitigate CVE-2025-67886, ensure that appropriate permission levels are set for the Translate Module, restricting write access as necessary.
Is the behavior described in CVE-2025-67886 intended?
The supplier disputes the characterization of CVE-2025-67886 as a vulnerability, stating that the behavior is intended for high-privileged users.