CVE-2020-15227
high · 8.7A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
8.7
CVSS
34.4%
EPSS (exploit prob.)
98th
EPSS percentile
2020-10-01
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-74CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nette | application | >= 2.0.0, < 2.0.19 |
| nette | application | >= 2.1.0, < 2.1.13 |
| nette | application | >= 2.2.0, < 2.2.10 |
| nette | application | >= 2.3.0, < 2.3.14 |
| nette | application | >= 2.4.0, < 2.4.16 |
| nette | application | >= 3.0.0, < 3.0.6 |
| debian | debian_linux | 9.0 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94
- https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html
- https://packagist.org/packages/nette/application
- https://packagist.org/packages/nette/nette
- https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94
- https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html
- https://packagist.org/packages/nette/application
- https://packagist.org/packages/nette/nette
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-15227