Bitrix Site Manager - Remote Code Execution
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. References: https://alt3r.eg0.ru/p0c5/attacking_bitrix.pdf https://pentestnotes.ru/notes/bitrix_pentest_full/#rce-vote_agentphp-cve-2022-27228 https://nvd.nist.gov/vuln/detail/CVE-2022-27228 Remediation: Update to version 21.0.100 or later.
Used 3.6k times · domain, subdomain, ipv4