Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-8880 | A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot of the component Template Handler. The manipulation of the argument username/email/captcha leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The project maintainer was informed early about the issue. Investigation shows that playSMS up to 1.4.3 contained a fix but later versions re-introduced the flaw. As long as the latest version of the playsms/tpl package is used, the software is not affected. Version >=1.4.4 shall fix this issue for sure. NVD description · AI analysis pending | 6.3 | <1% | PoC |
| — | |
| CVE-2024-6469 +1 in the same advisory: …6470 | A vulnerability was found in playSMS 1.4.3. A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list of the component Template Handler. The manipulation of the argument IP address with the input {{`id`} leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-270277 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-6251 | A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the file /index.php?app=main&inc=feature_phonebook&op=phonebook_list of the component New Phonebook Handler. The manipulation of the argument name/email leads to basic cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269418 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2022-47034 | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication. A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2021-40373 | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via th playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2020-15018 | playSMS through 1.4.3 is vulnerable to session fixation. playSMS through 1.4.3 is vulnerable to session fixation. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2020-8644 | Unauthenticated Server-Side Template Injection RCE in PlaySMS before 1.4.3 CVE-2020-8644 is a server-side template injection (CWE-94) in PlaySMS, an open-source SMS gateway web application, caused by failure to sanitize attacker-supplied strings before they are processed as templates. An unauthenticated attacker triggers the flaw by submitting a crafted string to the vulnerable web interface (reached via index.php per the public advisories), which the server then evaluates as a template, executing attacker-controlled code. Successful exploitation yields pre-authentication remote code execution with the privileges of the web service, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). All PlaySMS deployments running versions prior to 1.4.3 are affected. The flaw has public proof-of-concept exploits (NCC Group advisory and PacketStorm, February 2020), was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 confirming in-the-wild exploitation, and carries a very high EPSS score of 86.7% (100th percentile) for exploitation within 30 days. Do: Upgrade PlaySMS to version 1.4.3 or later per vendor instructions, as listed in the CISA KEV required action. If upgrading is delayed, restrict internet access to the PlaySMS web interface (e.g., allowlist trusted source IPs or place it behind an authenticated proxy), since exploitation requires no authentication. Administrators of internet-exposed instances should also review logs for signs of compromise given confirmed in-the-wild exploitation. | 9.8 | 87% | KEV PoC ×2 |
| nichelikely only hundreds to a low few thousand internet-exposed instances (no authoritative install counts in the record) | |
| CVE-2018-18387 | playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse. playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2017-9101 | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the n import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file. NVD description · AI analysis pending | 9.8 | 77% | PoC |
| — | |
| CVE-2017-9080 | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection. NVD description · AI analysis pending | 8.8 | 62% | PoC ×2 |
| — |