Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q4r-f47x-9m97

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Bitrix24 contains an authenticated remote code execution vulnerability that allows logged-in attackers to execute arbitrary system commands through the PHP command line admin interface. Attackers can leverage the vulnerability by sending crafted POST requests to the administrative endpoint with system commands to execute code with the web application's privileges.

Bitrix24 contains an authenticated remote code execution vulnerability that allows logged-in attackers to execute arbitrary system commands through the PHP command line admin interface. Attackers can leverage the vulnerability by sending crafted POST requests to the administrative endpoint with system commands to execute code with the web application's privileges.

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

nvd
26 дней назад

Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-862