Executive brief
PlaySMS before version 1.4.3 contains a server-side template injection (SSTI) vulnerability due to improper sanitization of input strings. An unauthenticated remote attacker can exploit this to execute arbitrary code on the server.
Affected products
- PlaySMS PlaySMS before 1.4.3
Timeline
- 2020-02-05: disclosed: PlaySMS 1.4.3 released to address the vulnerability
- 2020-02-05: advisory: NVD Published Date
- 2020-02-11: other: Technical advisory published by NCC Group
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog