Unrated severityNVD Advisory· Published Sep 18, 2020· Updated Aug 4, 2024
Unauthenticated Remote Code Execution in SOY CMS
CVE-2020-15188
Description
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.
Affected products
1- Range: < 3.0.2.328
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/inunosinsi/soycms/issues/10mitrex_refsource_MISC
- github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020mitrex_refsource_MISC
- github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jpmitrex_refsource_CONFIRM
- www.youtube.com/watchmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.