CVE-2020-8644

9.8CRITICAL

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

Published: 2/5/2020Updated: 11/7/2025

CISA Known Exploited Vulnerability

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

Due Date:

2022-05-03

Description

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

AI AnalysisPowered by AI

Affected Products

playsmsplaysms

Available Exploits (1)

References