CVE-2020-8644

9.8CRITICAL

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

发布于: 2/5/2020更新于: 11/7/2025

CISA已知被利用漏洞

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

所需操作:

Apply updates per vendor instructions.

截止日期:

2022-05-03

描述

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

AI分析AI驱动

受影响产品

playsmsplaysms

可用漏洞利用 (1)

参考资料