Junglewise Threat Intelligence

CVE-2020-8644: PlaySMS Server-Side Template Injection Vulnerability

CVE-2020-8644 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Executive brief

PlaySMS before version 1.4.3 contains a server-side template injection (SSTI) vulnerability due to improper sanitization of input strings. An unauthenticated remote attacker can exploit this to execute arbitrary code on the server.

Affected products

  • PlaySMS PlaySMS before 1.4.3

Timeline

  • 2020-02-05: disclosed: PlaySMS 1.4.3 released to address the vulnerability
  • 2020-02-05: advisory: NVD Published Date
  • 2020-02-11: other: Technical advisory published by NCC Group
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog