CVE-2020-15227
Summary
| CVE | CVE-2020-15227 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-01 19:15:00 UTC |
| Updated | 2021-11-18 16:47:00 UTC |
| Description | Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2617-1] php-nette security update |
MLIST |
lists.debian.org |
|
| nette/application - Packagist |
MISC |
packagist.org |
Third Party Advisory |
| Potential Remote Code Execution vulnerability · Advisory · nette/application · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| nette/nette - Packagist |
MISC |
packagist.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178512 Debian Security Update for php-nette (DLA 2617-1)
- 199262 Ubuntu Security Notification for Nette Vulnerability (USN-5983-1)