{"api_version":"1","generated_at":"2026-07-23T14:33:03+00:00","cve":"CVE-2020-15188","urls":{"html":"https://cve.report/CVE-2020-15188","api":"https://cve.report/api/cve/CVE-2020-15188.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15188","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15188"},"summary":{"title":"CVE-2020-15188","description":"SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-09-18 17:15:00","updated_at":"2020-09-29 14:04:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://github.com/inunosinsi/soycms/issues/10","name":"https://github.com/inunosinsi/soycms/issues/10","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Unauthenticated Remote Code Execution (RCE) in SoyCMS · Issue #10 · inunosinsi/soycms · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp","name":"https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"Unauthenticated Remote Code Execution (RCE) in SOY CMS · Advisory · inunosinsi/soycms · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020","name":"https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Fix RCE: Change serialize/unserialize to json encode/decode by stypr · Pull Request #12 · inunosinsi/soycms · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be","name":"https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"(CVE-2020-15188) SoyCMS: Unauthenticated Remote Code Execution - YouTube","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15188","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15188","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15188","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brassica","cpe5":"soy_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15188","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brassica","cpe5":"soy_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-15188","STATE":"PUBLIC","TITLE":"Unauthenticated Remote Code Execution in SOY CMS"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"soycms","version":{"version_data":[{"version_value":"< 3.0.2.328"}]}}]},"vendor_name":"inunosinsi"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"{\"CWE-502\":\"Deserialization of Untrusted Data\"}"}]}]},"references":{"reference_data":[{"name":"https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp","refsource":"CONFIRM","url":"https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp"},{"name":"https://github.com/inunosinsi/soycms/issues/10","refsource":"MISC","url":"https://github.com/inunosinsi/soycms/issues/10"},{"name":"https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020","refsource":"MISC","url":"https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020"},{"name":"https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be","refsource":"MISC","url":"https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be"}]},"source":{"advisory":"GHSA-hrrx-m22r-p9jp","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-09-18 17:15:00","lastModifiedDate":"2020-09-29 14:04:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:brassica:soy_cms:*:*:*:*:*:*:*:*","versionEndExcluding":"3.0.2.328","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15188","Ordinal":"176567","Title":"CVE-2020-15188","CVE":"CVE-2020-15188","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15188","Ordinal":"1","NoteData":"SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15188","Ordinal":"2","NoteData":"2020-09-18","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15188","Ordinal":"3","NoteData":"2020-09-18","Type":"Other","Title":"Modified"}]}}}