Lucene search

K
attackerkbAttackerKBAKB:77CE3B54-22E1-45AA-89C0-8CB495618D6C
HistoryFeb 05, 2020 - 12:00 a.m.

CVE-2020-8644

2020-02-0500:00:00
attackerkb.com
21

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.958 High

EPSS

Percentile

99.5%

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

Recent assessments:

touhidshaikh at March 12, 2020 4:40pm UTC reported:

Description

This module exploits a Preauth Server-Side Template Injection leads remote code execution vulnerability in PlaySMS Before Version 1.4.3. This issue is caused by Double processes a server-side template by Custom PHP Template system called ‘TPL’.which is used in PlaySMS template engine location src/Playsms/Tpl.php:_compile(). When Attacker supply username with a malicious payload and submit. This malicious payload first processes by TPL and save the value in the current template after this value goes for the second process which result in code execution.
The TPL(<https://github.com/antonraharja/tpl&gt;) template language is vulnerable to PHP code injection

Vulnerable Application

Available at Source Forge

Metasploit Exploit (Written By Me)

Available at Github PR

Exploit Video PoC

Available at Youtube Video

Assessed Attacker Value: 3
Assessed Attacker Value: 3Assessed Attacker Value: 5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.958 High

EPSS

Percentile

99.5%