First published: Thu Sep 17 2020(Updated: )
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Soy Cms Project Soy Cms | <3.0.2.328 | |
Soy Inquiry Project Soy Inquiry | <2.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15182 is a vulnerability affecting the SOY Inquiry component of SOY CMS, allowing for Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE).
CVE-2020-15182 has a severity rating of 9.6, which is classified as critical.
Versions 2.0.0.3 and earlier of SOY Inquiry are affected by CVE-2020-15182.
Remote attackers can exploit CVE-2020-15182 to force administrators to edit files once the administrator loads a specially crafted page.
You can find more information about CVE-2020-15182 on GitHub Pull Request #15 and GitHub Security Advisories GHSA-j2qw-747j-mfv4. You can also watch a video demonstration at youtu.be/ffvKH3gwyRE.