CVE-2020-15227

High PUBLISHED

Remote Code Execution vulnerability

nette · application

Not yet in CISA KEV

PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
PoC available
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.7 High

At a Glance

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

nuclei_scanner
CVE Published
Oct 01, 2020
Exploitation Reported
Jul 11, 2025
CVSS
8.7 High
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
nette
application

>= 2.0.0, < 2.0.19

Affected
nette
application

>= 2.1.0, < 2.1.13

Affected
nette
application

>= 2.2.0, < 2.2.10

Affected
nette
application

>= 2.3.0, < 2.3.14

Affected
nette
application

>= 2.4.0, < 2.4.16

Affected
nette
application

>= 3.0.0, < 3.0.6

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.