ZeroHour

CVE-2020-8644

KEV PoC ×2niche

Unauthenticated Server-Side Template Injection RCE in PlaySMS before 1.4.3

CISA: PlaySMS Server-Side Template Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2020-8644 is a server-side template injection (CWE-94) in PlaySMS, an open-source SMS gateway web application, caused by failure to sanitize attacker-supplied strings before they are processed as templates. An unauthenticated attacker triggers the flaw by submitting a crafted string to the vulnerable web interface (reached via index.php per the public advisories), which the server then evaluates as a template, executing attacker-controlled code. Successful exploitation yields pre-authentication remote code execution with the privileges of the web service, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). All PlaySMS deployments running versions prior to 1.4.3 are affected. The flaw has public proof-of-concept exploits (NCC Group advisory and PacketStorm, February 2020), was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 confirming in-the-wild exploitation, and carries a very high EPSS score of 86.7% (100th percentile) for exploitation within 30 days.

What to do: Upgrade PlaySMS to version 1.4.3 or later per vendor instructions, as listed in the CISA KEV required action. If upgrading is delayed, restrict internet access to the PlaySMS web interface (e.g., allowlist trusted source IPs or place it behind an authenticated proxy), since exploitation requires no authentication. Administrators of internet-exposed instances should also review logs for signs of compromise given confirmed in-the-wild exploitation.

Affected
PlaySMSAll versions prior to 1.4.3
Estimated exposure
nichelikely only hundreds to a low few thousand internet-exposed instances (no authoritative install counts in the record) — PlaySMS is a niche, self-hosted open-source SMS gateway typically deployed on internal SMS infrastructure rather than mass-market software, and public internet scans have surfaced only limited numbers of exposed instances; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

CISA Known Exploited Vulnerability
Affected
PlaySMS PlaySMS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
playsms
Products
playsms
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.