peter bassill · operator
$ cve CVE-2020-15188 JSON

CVE-2020-15188

10.0
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS5.08% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2020-09-18
Last modified2026-06-17

Affected (1)

VendorProduct
brassicasoy cms

References

→ the Explorer  ·  watch your stack  ·  NVD