← back
CVE-2020-15143

Remote Code Execution in SyliusResourceBundle

CVSS 7.7 HIGHEPSS 1.9%CWE-74
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 1.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →