High severity8.7NVD Advisory· Published Oct 1, 2020· Updated Jun 17, 2026
CVE-2020-15227
CVE-2020-15227
Description
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nette/applicationPackagist | >= 2.2.0, < 2.2.10 | 2.2.10 |
nette/applicationPackagist | >= 2.3.0, < 2.3.14 | 2.3.14 |
nette/applicationPackagist | >= 2.4.0, < 2.4.16 | 2.4.16 |
nette/applicationPackagist | >= 3.0.0, < 3.0.6 | 3.0.6 |
nette/applicationPackagist | >= 2.0.0, < 2.0.19 | 2.0.19 |
nette/applicationPackagist | >= 2.1.0, < 2.1.13 | 2.1.13 |
Affected products
4- nette/applicationv5Range: >= 2.0.0, < 2.0.19
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-8gv3-3j7f-wg94ghsaADVISORY
- github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94nvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2021/04/msg00003.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15227ghsaADVISORY
- packagist.org/packages/nette/applicationnvdThird Party AdvisoryWEB
- packagist.org/packages/nette/nettenvdThird Party AdvisoryWEB
- blog.nette.org/en/cve-2020-15227-potential-remote-code-execution-vulnerabilityghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/nette/application/CVE-2020-15227.yamlghsaWEB
News mentions
0No linked articles in our index yet.