CVE-2020-15188
Summary
| CVE | CVE-2020-15188 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-18 17:15:00 UTC |
| Updated | 2020-09-29 14:04:00 UTC |
| Description | SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Unauthenticated Remote Code Execution (RCE) in SoyCMS · Issue #10 · inunosinsi/soycms · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Unauthenticated Remote Code Execution (RCE) in SOY CMS · Advisory · inunosinsi/soycms · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| Fix RCE: Change serialize/unserialize to json encode/decode by stypr · Pull Request #12 · inunosinsi/soycms · GitHub | MISC | github.com | Patch, Third Party Advisory |
| (CVE-2020-15188) SoyCMS: Unauthenticated Remote Code Execution - YouTube | MISC | www.youtube.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.