CVE-2020-15227

Medium PUBLISHED

Remote Code Execution vulnerability

nette · application

Not yet in CISA KEV

PoC available

Recommended Action

Review exposure in your environment and monitor for exploitation signals before broader rollout.

Confidence
Medium
Exploitation Status
PoC available
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.7 High

At a Glance

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

nuclei_scanner
Published
Oct 01, 2020
First Seen
Jul 11, 2025
CVSS
8.7 High
EPSS
Remote No user interaction Unauthenticated

Recommended Actions

  • Review exposure in your environment and monitor for exploitation signals before broader rollout.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.