ZeroHour

CVE-2020-15227

CVSS 3.1
9.8 critical
EPSS
34%p98
Published
()
Modified
Description

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

Vendors
nettedebian
Products
application, debian linux
Weakness
CWE-74, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.