vendor:
PlaySMS
by:
Touhid M.Shaikh
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: PlaySMS
Affected Version From: 1.4
Affected Version To: 1.4
Patch Exists: NO
Related CWE: N/A
CPE: a:playsms:playsms:1.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
PlaySMS 1.4 Remote Code Execution (to Poisoning admin log)
Remote Code Execution in Admin Log. In PlaySMS Admin have a panel where he/she monitor User status. Admin Can see Whose Online. Using this functionality we can exploit RCE in Whose Online page. When Any user Logged in the playSMS application. Some user details log on Whose Online panel like 'Username', 'User-Agent', 'Current IP', etc.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.