S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-8644 Scanner

CVE-2020-8644 scanner - Server Side Template Injection (SSTI) vulnerability in PlaySMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-8644
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PlaySMS is an open-source web-based application used for sending and receiving SMS messages. This platform enables users to send messages in bulk and manage them using a web interface or through a mobile app. It is widely used in various industries, including healthcare, finance, marketing, and education. PlaySMS provides a simple, yet effective way for businesses to reach out to their clients quickly and efficiently.

CVE-2020-8644 is a critical vulnerability detected in PlaySMS before version 1.4.3. This vulnerability allows attackers to exploit a pre-auth server-side template injection flaw that leads to remote code execution. The issue occurs due to a double processing of a server-side template with a custom PHP template system called TPL. Attackers can submit a malicious payload via a username and store it in a TPL template. When the template is rendered a second time, it results in code execution.

Exploiting this vulnerability can lead to devastating consequences for businesses using PlaySMS. Attackers can gain unauthorized access to sensitive data, manipulate SMS messages, and even take over the entire system. This would result in significant losses to businesses, including financial, reputational, and legal penalties.

Thanks to the pro features offered by the s4e.io platform, businesses can quickly and easily learn about vulnerabilities in their digital assets. By subscribing to this service, businesses can stay ahead of potential threats and take proactive measures to protect their systems. The platform offers a comprehensive range of features that enable businesses to detect, prioritize and manage vulnerabilities effectively. By using this service, businesses can ensure the security of their digital assets and mitigate the risk of cyber attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses can take the following precautions:

  • Upgrade PlaySMS to version 1.4.3 or later
  • Apply security updates regularly
  • Implement a monitoring system that detects any unusual activity in the system
  • Use strong passwords and enable two-factor authentication
  • Limit access to the application to only authorized personnel

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-8644 scanner - Server Side Template Injection (SSTI) vulnerability in PlaySMS | S4E