vendor:
Bitrix24
by:
picaro_o
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: Bitrix24
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Linux
2022
Bitrix24 – Remote Code Execution (RCE) (Authenticated)
Bitrix24 is a web-based collaboration platform that allows users to manage their projects, tasks, documents, and customer relationships. A vulnerability in the platform allows an authenticated user to execute arbitrary code on the server. This exploit was discovered by picaro_o in April 2022 and tested on Linux OS. The exploit requires the user to provide the Bitrix URL, username, and password. The exploit then uses a POST request to authenticate the user and a GET request to extract the session ID. The exploit then uses a POST request to execute the arbitrary code on the server.
Mitigation:
Users should update to the latest version of Bitrix24 and ensure that all users have strong passwords.