CVE-2020-15143
Remote Code Execution in SyliusResourceBundle
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Affected products
Sylius · SyliusResourceBundleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →