6.3
CVE-2025-67886
- EPSS 1.03%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 08.05.2026 18:16:32
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload new translated pages to the website.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.03% | 0.591 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://www.bitrix24.com/self-hosted/
https://seclists.org/fulldisclosure/2025/Dec/21
https://karmainsecurity.com/pocs/CVE-2025-67886.php
https://dev.1c-bitrix.ru/learning/course/?COURSE_ID=43&LESSON_ID=3055
https://dev.1c-bitrix.ru/api_help/translate/index.php
http://seclists.org/fulldisclosure/2025/Dec/21