← All CVEs

CVE-2020-15227

high · 8.7

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

8.7
CVSS
34.4%
EPSS (exploit prob.)
98th
EPSS percentile
2020-10-01
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-74CWE-94

Affected products

VendorProductAffected versions
netteapplication>= 2.0.0, < 2.0.19
netteapplication>= 2.1.0, < 2.1.13
netteapplication>= 2.2.0, < 2.2.10
netteapplication>= 2.3.0, < 2.3.14
netteapplication>= 2.4.0, < 2.4.16
netteapplication>= 3.0.0, < 3.0.6
debiandebian_linux9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-15227