In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
References
Link | Resource |
---|---|
https://helpdesk.bitrix24.com/open/15536776/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-22T17:27:57
Updated: 2022-03-22T17:27:57
Reserved: 2022-03-17T00:00:00
Link: CVE-2022-27228
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-03-22T18:15:08.553
Modified: 2022-03-28T20:40:29.130
Link: CVE-2022-27228
JSON object: View
Redhat Information
No data.
CWE