CVE-2020-8644
KEV PoC ×2nicheUnauthenticated Server-Side Template Injection RCE in PlaySMS before 1.4.3
CISA: PlaySMS Server-Side Template Injection Vulnerability
CVE-2020-8644 is a server-side template injection (CWE-94) in PlaySMS, an open-source SMS gateway web application, caused by failure to sanitize attacker-supplied strings before they are processed as templates. An unauthenticated attacker triggers the flaw by submitting a crafted string to the vulnerable web interface (reached via index.php per the public advisories), which the server then evaluates as a template, executing attacker-controlled code. Successful exploitation yields pre-authentication remote code execution with the privileges of the web service, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). All PlaySMS deployments running versions prior to 1.4.3 are affected. The flaw has public proof-of-concept exploits (NCC Group advisory and PacketStorm, February 2020), was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 confirming in-the-wild exploitation, and carries a very high EPSS score of 86.7% (100th percentile) for exploitation within 30 days.
What to do: Upgrade PlaySMS to version 1.4.3 or later per vendor instructions, as listed in the CISA KEV required action. If upgrading is delayed, restrict internet access to the PlaySMS web interface (e.g., allowlist trusted source IPs or place it behind an authenticated proxy), since exploitation requires no authentication. Administrators of internet-exposed instances should also review logs for signs of compromise given confirmed in-the-wild exploitation.
| PlaySMS | All versions prior to 1.4.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- Affected
- PlaySMS PlaySMS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- playsms
- Products
- playsms
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.