CVE-2025-67887: Code Injection
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67887?
CVE-2025-67887 has a critical severity score of 9.8 according to the CVSS 3.1 metrics.
What type of vulnerability is represented by CVE-2025-67887?
CVE-2025-67887 is classified as a Code Injection vulnerability allowing for Remote Code Execution.
How do I fix CVE-2025-67887?
To mitigate CVE-2025-67887, ensure that proper access controls are in place to restrict SOURCE/WRITE permissions for the Translate Module.
Which software versions are affected by CVE-2025-67887?
CVE-2025-67887 affects 1C-Bitrix versions up to 25.100.500.
What is the potential impact of exploiting CVE-2025-67887?
Exploitation of CVE-2025-67887 could lead to Remote Code Execution, allowing an attacker to upload and execute malicious code.