CVE-2020-15227
Last modified
CVE-2020-15227 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.. EPSS estimates a 35.23% chance of exploitation in the next 30 days.
Description
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nette | Application | >= 2.0.0, < 2.0.19 |
| Nette | Application | >= 2.1.0, < 2.1.13 |
| Nette | Application | >= 2.2.0, < 2.2.10 |
| Nette | Application | >= 2.3.0, < 2.3.14 |
| Nette | Application | >= 2.4.0, < 2.4.16 |
| Nette | Application | >= 3.0.0, < 3.0.6 |
| Debian | Debian Linux | 9.0 |
References
- https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00003.htmlMailing List, Third Party Advisory
- https://packagist.org/packages/nette/applicationThird Party Advisory
- https://packagist.org/packages/nette/netteThird Party Advisory
- https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00003.htmlMailing List, Third Party Advisory
- https://packagist.org/packages/nette/applicationThird Party Advisory
- https://packagist.org/packages/nette/netteThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15227?
How severe is CVE-2020-15227?
How do I fix CVE-2020-15227?
Are you affected by CVE-2020-15227?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
