helpdesk.bitrix24.comConfirmation
https://helpdesk.bitrix24.com/open/15536776 CVE-2022-27228
CRITICALNuclei
bitrix24 bitrix24 Improper Input Validation
Record summary
CVE-2022-27228 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 7, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bitrix24Browse bitrix24 / bitrix24 | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALBitrix Site Manager - Remote Code ExecutionCVSS 9.8
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.
Impact
Unauthenticated attackers can execute arbitrary code remotely, potentially leading to full system compromise.
Remediation
Update to version 21.0.100 or later.
WeaknessesCWE-20
Authorstheamanrawat
Template tagscvecve2022bitrixfile-uploadrceintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:bitrix24:bitrix24:*:*:*:*:*:*:*:*
Shodan: /bitrix/p3p.xml
FOFA: body="/bitrix/"
https://alt3r.eg0.ru/p0c5/attacking_bitrix.pdf https://pentestnotes.ru/notes/bitrix_pentest_full/#rce-vote_agentphp-cve-2022-27228 https://nvd.nist.gov/vuln/detail/CVE-2022-27228
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27228