Close the vulnerability on the Bitrix website.
Bitrix.CVE-2022-27228
Level of Danger:
Status: Vulnerability
Vulnerability has been fixed in Bitrix vote module.The vulnerability allows arbitrary code execution.Versions: < 21.0100Affected file: bitrix/modules/vote/lib/attachment/connector.php. Remote Code Execution (RCE)https://dev.1c-bitrix.ru/docs/versions.php?lang=ru&module=vote , https://nvd.nist.gov/vuln/detail/CVE-2022-27228 .Update the module to the latest version.2nd
HTTPS://2ip.ru/site-virus-scaner/ also complain, here is so
2ip Safe Browsing: Suspicion of a virus!The site finds iframe entries linking to doubtful sites or an offensive code.More information about the possible causes of the problem is here.
HTTPS://dev.1c-bitrix.ru/support/forum/forum6/topic147346/?PAGEN_1=13
HTTPS://dzen.ru/media/mills/virusy-na-1sbitriks-2022g-62d158c2c4469e06dcb158a4
HTTPS://kuratov.ru/blog/bitriks-v-bede-sajty-na-bitriks-podverglis-atake/
I am looking for a person who can
1 .Discover the primary cause
Eliminating vulnerabilities
3. to provide (relative) guarantee for the absence of fractures of this vulnerability;
Client's review of cooperation with Vasyl K.
Close the vulnerability on the Bitrix website.Vasil is not just a good expert, but also a very decent person. With understanding and tolerance to the position of the customer, that according to my own experience is sufficient a rare property;
The question is resolved. Consultations are provided. I planned the collaboration in the future.
I congratulate everyone.
The only thing that should be agreed in advance is that it is a matter of time to check the work. But can this be a question to the stock market? As it turns out, it is necessary to close the project quickly, not that the executive rating is decreasing? How strange it is to me, not comfortable, because I need time to check out...
Freelancer's review of cooperation with Andrey Chernuha
Close the vulnerability on the Bitrix website.When the customer without exaggeration is great, many letters are left.. I'm glad to cooperate. I am very pleased to work with Andrew.
-
955 24 0 Good day, ready to help solve the problems with Bitrix vulnerability, a great experience of working with this engine - contact us.
-
5531 105 2 I do it. He has treated / saved websites on Bitrix many times.
There are certificates of admin, host Bitrix.
-
2928 81 0 Hello to you. Ready to work now!
Treatment and protection of the site is a lifetime guarantee.
What I will do:
1 . Remove viruses and shells.
2nd I resolve the spam issue.
Three I will update your CMS and scripts. I close the hole.
4 . We will set up a system of protection against fractures.
and 5. Free safety consultation.
… The deadline is 1 day.
I will set up a virus checking system.
Check once a day for the most popular antivirus.
This script is a gift for 1 year.
The price for 1 site is $99
Discount for ordering 3x or more sites.
The guarantee:
First option: 1 year guarantee. (If you stay in your host)
The second option is life guarantee!!! (When transferred to hosting with increased protection)
Contact the UW. and Dmitry!
Current freelance projects in the category PHP
GoPos IntegrationHello, has anyone done an integration of GoPos with a custom website for a restaurant in Poland? I need help, their documentation is very sparse, there is only swagger and it lacks descriptions. https://app.gopos.io/doc/swagger-ui/index.html The essence is this: we used their… PHP, Web Programming ∙ 5 hours 43 minutes back ∙ 15 proposals |
Write meta data for ALT using AIA website on Laravel, the site has many images for which it is necessary to automatically generate correct semantic and relevant ALT descriptions for the images, with the possibility of verification. AI & Machine Learning, PHP ∙ 1 day 3 hours back ∙ 32 proposals |
A developer is needed to complete and integrate a project for automatic data collection and processing.
16 USD
The main part of the parser has already been implemented. The parser works in a Windows environment through Microsoft Edge: the site has anti-bot protection, so data collection is performed not through direct HTTP requests, but through a live browser session. The scripts control… PHP, Web Programming ∙ 1 day 8 hours back ∙ 24 proposals |
Updating plugins and themes for the WP site putevka.uz"A technical audit of the WordPress site needs to be conducted, checking the relevance, security, and compatibility of the installed plugins and theme. Based on the results, legal options for updating, replacing outdated solutions, or transitioning to officially available… HTML & CSS, PHP ∙ 1 day 11 hours back ∙ 38 proposals |
Integration of the "Where to Watch" block (Laravel / Livewire)It is necessary to implement the integration of an external streaming platform for a website about movies and series on Laravel / Livewire. What needs to be done: Implement the import of an external content catalog that is updated once a day. Match content by IMDb ID and/or TMDB… PHP, Web Programming ∙ 2 days 1 hour back ∙ 40 proposals |