Skip to content
COOEY

EXPOSURES › CVE-2020-8644

CVE-2020-8644

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8644 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

PlaySMS suffered a server-side template injection vulnerability allowing remote code execution.

The PlaySMS server contained a server-side template injection flaw that permitted remote code execution, enabling attackers to execute arbitrary commands on the system. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability (KEV) that could lead to system compromise, data exfiltration, or ransomware deployment. Organizations must ensure all communication and messaging platforms are patched against known CVEs and monitored for exploitation in the wild.

Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed remote code execution, indicating a severe, avoidable failure to patch known security flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows remote code execution, indicating a severe security failure in PlaySMS.
cooey ↗ severe-fallout -0.60
Vulnerability allows remote code execution, indicating a severe security failure in PlaySMS.
"PlaySMS contains a server-side template injection vulnerability that allows for remote code execution."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.