CVE-2020-15227
php-nette - security update
8.7
HIGH
CVSS 3.1
EPSS 35.2%
Description
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ### Impact Code injection, possible remote code execution. ### Patches Fixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13
How to fix CVE-2020-15227
To remediate CVE-2020-15227, upgrade the affected package to a fixed version below.
- —upgrade to 2.2.10 or later
Is CVE-2020-15227 being exploited?
Moderate — EPSS is 35.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.2.0, < 2.2.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |