CVE-2020-8644
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- Published Feb 5, 2020
- CVSS 9.8 critical
- 86.7% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
- A fix is available