{"api_version":"1","generated_at":"2026-07-23T13:02:27+00:00","cve":"CVE-2020-15227","urls":{"html":"https://cve.report/CVE-2020-15227","api":"https://cve.report/api/cve/CVE-2020-15227.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15227","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15227"},"summary":{"title":"CVE-2020-15227","description":"Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-10-01 19:15:00","updated_at":"2021-11-18 16:47:00"},"problem_types":["CWE-94"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html","name":"[debian-lts-announce] 20210404 [SECURITY] [DLA 2617-1] php-nette security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2617-1] php-nette security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://packagist.org/packages/nette/application","name":"N/A","refsource":"MISC","tags":["Third Party Advisory"],"title":"nette/application - Packagist","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94","name":"https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Potential Remote Code Execution vulnerability · Advisory · nette/application · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://packagist.org/packages/nette/nette","name":"N/A","refsource":"MISC","tags":["Third Party Advisory"],"title":"nette/nette - Packagist","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15227","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15227","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15227","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15227","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nette","cpe5":"application","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15227","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nette","cpe5":"application","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-15227","qid":"178512","title":"Debian Security Update for php-nette (DLA 2617-1)"},{"cve":"CVE-2020-15227","qid":"199262","title":"Ubuntu Security Notification for Nette Vulnerability (USN-5983-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-15227","STATE":"PUBLIC","TITLE":"Remote Code Execution vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"application","version":{"version_data":[{"version_value":">= 2.0.0, < 2.0.19"},{"version_value":">= 2.1.0, < 2.1.13"},{"version_value":">= 2.2.0, < 2.2.10"},{"version_value":">= 2.3.0, < 2.3.14"},{"version_value":">= 2.4.0, < 2.4.16"},{"version_value":">= 3.0.0, < 3.0.6"}]}}]},"vendor_name":"nette"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}]}]},"references":{"reference_data":[{"name":"https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94","refsource":"CONFIRM","url":"https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94"},{"refsource":"MISC","url":"https://packagist.org/packages/nette/application","name":"https://packagist.org/packages/nette/application"},{"refsource":"MISC","url":"https://packagist.org/packages/nette/nette","name":"https://packagist.org/packages/nette/nette"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210404 [SECURITY] [DLA 2617-1] php-nette security update","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html"}]},"source":{"advisory":"GHSA-8gv3-3j7f-wg94","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-10-01 19:15:00","lastModifiedDate":"2021-11-18 16:47:00","problem_types":["CWE-94"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"2.4.0","versionEndExcluding":"2.4.16","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"2.3.0","versionEndExcluding":"2.3.14","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.10","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nette:application:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.19","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15227","Ordinal":"176606","Title":"CVE-2020-15227","CVE":"CVE-2020-15227","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15227","Ordinal":"1","NoteData":"Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15227","Ordinal":"2","NoteData":"2020-10-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15227","Ordinal":"3","NoteData":"2021-04-04","Type":"Other","Title":"Modified"}]}}}