LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8644: PlaySMS Server-Side Template Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8644 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

CVE-2020-8644 is a server-side template injection flaw in PlaySMS that can lead to remote code execution. Organizations running PlaySMS should treat this as a high-priority issue because successful abuse can give an attacker control over the application host and any data or messaging functions it handles.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact affected releases, fixed versions, and deployment notes directly against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-94 (code injection). In a server-side template injection (SSTI) weakness, user-controlled input is improperly incorporated into a server-side template engine. When the engine evaluates that input, an attacker who can supply crafted template expressions may cause the application to execute arbitrary code in the context of the PlaySMS process.

Abuse typically requires the attacker to reach a feature that renders or processes templates with insufficient sanitization or sandboxing. Once code execution is achieved, the attacker can run commands, read or alter files, or pivot further into the environment. Specific exploit mechanics, required privileges, and exact injection points are not provided in the given facts; treat any public proof-of-concept material cautiously and validate behavior only in a controlled lab against the vendor’s description.

Am I affected? How to find it in your systems

PlaySMS is messaging/SMS gateway software commonly deployed on Linux servers, often in telecom, notification, or internal communications roles. It may appear as a standalone web application or as part of a larger messaging stack.

If you cannot confirm the version or patch status, assume the instance is in scope until verified.

How to remediate

Patch first. Apply the updates provided by the vendor exactly as described in the official advisory (CISA’s required action is to apply updates per vendor instructions). After patching:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

Document the exception, set a firm patch deadline, and reassess risk daily until remediated. Known ransomware use is not documented for this CVE.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full host compromise and data theft. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate the host, preserve volatile and disk evidence, and assess what messaging data, credentials, or adjacent systems may have been accessed. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials have appeared in prior public breaches, then force password resets and enable multi-factor authentication where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPlaySMS · PlaySMS
WeaknessCWE-94
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities