VYPR
Critical severity9.8NVD Advisory· Published Oct 22, 2021· Updated Jun 17, 2026

CVE-2020-23037

CVE-2020-23037

Description

Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Portable/Playable2 versions
    cpe:2.3:a:portable:playable:9.18:*:*:*:*:ipados:*:*+ 1 more
    • cpe:2.3:a:portable:playable:9.18:*:*:*:*:ipados:*:*
    • cpe:2.3:a:portable:playable:9.18:*:*:*:*:iphone_os:*:*
  • Portable Ltd/Playablecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =9.18

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.