漏洞描述
PlaySMS before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
research.nccgroup.comhttps://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/↗playsms.orghttps://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-8644↗packetstormsecurity.comhttp://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html↗forum.playsms.orghttps://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704↗