← Back to browse · API

CVE-2020-15227

Severity
HIGH
CVSS
8.7
EPSS
0.35228
Risk score
47.13
CISA KEV
No
PoC
No
Published
2020-10-01
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-1420, GHSA-8GV3-3J7F-WG94
Products
nette:application 2.0.0, < 2.0.19, nette:application 2.1.0, < 2.1.13, nette:application 2.2.0, < 2.2.10, nette:application 2.3.0, < 2.3.14, nette:application 2.4.0, < 2.4.16, nette:application 3.0.0, < 3.0.6
Sources
euvd EUVD-2020-1420

Description

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

References