Description
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2617-1 | php-nette security update |
Github GHSA |
GHSA-8gv3-3j7f-wg94 | Potential Remote Code Execution vulnerability |
Ubuntu USN |
USN-5983-1 | Nette vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:08:22.829Z
Reserved: 2020-06-25T00:00:00.000Z
Link: CVE-2020-15227
No data.
Status : Modified
Published: 2020-10-01T19:15:12.797
Modified: 2024-11-21T05:05:08.170
Link: CVE-2020-15227
No data.
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA
Ubuntu USN