CVE-2017-9080: PlaySMS
High severity, CVSS 8.8. EPSS: 62.3% chance of exploitation in the next 30 days.
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.
Affected products
- PlaySMS PlaySMS: version 1.4 only
Published 2017-05-19. Last modified 2026-06-17.