CRITICAL KEV
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string
Published Feb 5, 2020 ·Due May 3, 2022
9.8
CRITICALCVSS 3.1
EPSS 86.69%
Description
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704 x_refsource_MISCBroken LinkRelease NotesVendor Advisory
- https://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/ x_refsource_MISCVendor Advisory
- https://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/ x_refsource_MISCExploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8644 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704 | x_refsource_MISCBroken LinkRelease NotesVendor Advisory | |
| https://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/ | x_refsource_MISCVendor Advisory | |
| https://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/ | x_refsource_MISCExploit | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8644 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 5, 2020
Updated Oct 21, 2025
Reserved Feb 5, 2020
Link CVE-2020-8644
CISA Vulnrichment
Updated Feb 4, 2025