CVE-2022-27228

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/03/2022
Last modified:
28/03/2022

Description

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitrix24:bitrix24:*:*:*:*:*:*:*:* 21.0.100 (excluding)


References to Advisories, Solutions, and Tools