PT-2024-39297 · Playsms · Playsms

Dhimitri

·

Published

2024-09-15

·

Updated

2024-09-20

·

CVE-2024-8880

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: playSMS versions 1.4.4 through 1.4.7
Description: A critical vulnerability has been found in playSMS, affecting an unknown function of the file /playsms/index.php?app=main&inc=core auth&route=forgot&op=forgot of the component Template Handler. The manipulation of the username, email, or captcha arguments leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations: To resolve the issue, upgrade the affected component to version >=1.4.4 or use the latest playsms/tpl package. As a temporary workaround, consider restricting access to the vulnerable Template Handler component until a patch is available. Avoid using the username, email, or captcha arguments in the affected API endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8880

Affected Products

Playsms