{"api_version":"1","generated_at":"2026-07-23T07:08:42+00:00","cve":"CVE-2015-8355","urls":{"html":"https://cve.report/CVE-2015-8355","api":"https://cve.report/api/cve/CVE-2015-8355.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-8355","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-8355"},"summary":{"title":"CVE-2015-8355","description":"Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) \"by\" parameter to admin/orion.extfeedbackform_efbf_forms.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-08-24 21:29:00","updated_at":"2018-10-09 19:58:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.htbridge.com/advisory/HTB23280","name":"https://www.htbridge.com/advisory/HTB23280","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://www.securityfocus.com/archive/1/537130/100/0/threaded","name":"20151216 SQL Injection in orion.extfeedbackform Bitrix Module","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-8355","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8355","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"8355","vulnerable":"1","versionEndIncluding":"2.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orion-soft","cpe5":"bitrix","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-8355","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) \"by\" parameter to admin/orion.extfeedbackform_efbf_forms.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20151216 SQL Injection in orion.extfeedbackform Bitrix Module","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/537130/100/0/threaded"},{"name":"https://www.htbridge.com/advisory/HTB23280","refsource":"MISC","url":"https://www.htbridge.com/advisory/HTB23280"}]}},"nvd":{"publishedDate":"2017-08-24 21:29:00","lastModifiedDate":"2018-10-09 19:58:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:orion-soft:bitrix:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"8355","Ordinal":"85373","Title":"CVE-2015-8355","CVE":"CVE-2015-8355","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"8355","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) \"by\" parameter to admin/orion.extfeedbackform_efbf_forms.php.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"8355","Ordinal":"2","NoteData":"2017-08-24","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"8355","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}