Vulnerability record · CVE-2020-8644 · published 5 February 2020
CVE-2020-8644: PlaySMS unauthenticated template injection code execution
Playsms · Playsms
PlaySMS before 1.4.3 fails to sanitize input from a malicious string, allowing server-side template injection that leads to code execution. The flaw is remotely reachable without authentication and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters to any internet-facing PlaySMS deployment.
Description
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS of 9.8, KEV listing and very high EPSS probability makes this an urgent patch.
What it is
PlaySMS before 1.4.3 fails to sanitize input from a malicious string, allowing server-side template injection that leads to code execution. The flaw is remotely reachable without authentication and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters to any internet-facing PlaySMS deployment.
Impact
An attacker can execute arbitrary code on the PlaySMS server, gaining full control of the application and its host. CVSS 3.1 rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the index.php request path, per the exploit reference title. The CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.
Exploitation
CISA added it to KEV on 2021-11-03 with a 2022-05-03 remediation due date, and EPSS shows a 30-day probability of 0.867 at the 99.7th percentile. Multiple references are tagged Exploit, including a public unauthenticated template injection code execution writeup.
What to do
- Upgrade PlaySMS to 1.4.3 or later per the vendor release notes.
- If immediate patching is not possible, remove internet exposure of PlaySMS and restrict access to trusted networks.
- Treat any internet-facing PlaySMS instance as compromised and hunt for injected template or web shell artifacts.
- Apply the CISA KEV required action and track remediation against the 2022-05-03 due date.
- Review web server and application logs for anomalous index.php requests.
Detection
- Search web logs for suspicious index.php requests containing template syntax or PHP code markers.
- Monitor for unexpected child processes spawned by the web server user.
- Look for newly created or modified files under the PlaySMS web root.
- Alert on outbound network connections originating from the PlaySMS host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-8644 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "PlaySMS Server-Side Template Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-8644 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8644), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.