⚡ Get unlimited AI threat intel — exploit-db.ai →
HIGH

CVE-2022-27228

⚡ Llama-3 AI Analysis

Executive Briefing

Bitrix24 broken access control enabling RCE via REST API — widely exploited by Russian threat actors against organizations in CIS region. Update Bitrix24 to latest version. Restrict REST API access to authenticated internal users only.

NVD Description

Broken access control in Bitrix24 cms allows remote attackers to modify content and perform code execution when REST API is exposed.

Want alerts for CVEs like this?

Exploit-DB.ai delivers real-time AI-triaged zero-day alerts directly to your inbox.

Activate Supernova →

Official Sources