CVE-2020-15188
10.0
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 5.08% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-09-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| brassica | soy cms |
References
- https://github.com/inunosinsi/soycms/issues/10
- https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020
- https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp
- https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be
- https://github.com/inunosinsi/soycms/issues/10
- https://github.com/inunosinsi/soycms/pull/12/commits/a75642989132dd25f74a13194b27c0986c3de020
- https://github.com/inunosinsi/soycms/security/advisories/GHSA-hrrx-m22r-p9jp
- https://www.youtube.com/watch?v=zAE4Swjc-GU&feature=youtu.be
→ the Explorer · watch your stack · NVD