PT-2024-39297 · Playsms · Playsms
Dhimitri
·
Published
2024-09-15
·
Updated
2024-09-20
·
CVE-2024-8880
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
playSMS versions 1.4.4 through 1.4.7
Description:
A critical vulnerability has been found in playSMS, affecting an unknown function of the file /playsms/index.php?app=main&inc=core auth&route=forgot&op=forgot of the component Template Handler. The manipulation of the
username, email, or captcha arguments leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.Recommendations:
To resolve the issue, upgrade the affected component to version >=1.4.4 or use the latest playsms/tpl package. As a temporary workaround, consider restricting access to the vulnerable Template Handler component until a patch is available. Avoid using the
username, email, or captcha arguments in the affected API endpoint until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Playsms