EDB-48335
remotephpVERIFIED
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
CVE-2020-8644
Metasploit4/16/2020
PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.
Apply updates per vendor instructions.
2022-05-03
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.