Skip to main content

CVE-2020-8163

Description

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the locals argument of a render call to perform a RCE.

NVD
Severity: HIGH
CVE ID: CVE-2020-8163
CVSS Score: 8.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

Nuclei Templates for CVE-2020-8163
lucasallan

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

Refrence: GitHub

h4ms1k

Enviroment and exploit to rce test

Refrence: GitHub

TK-Elliot

This is a exploit code for CVE-2020-8163

Refrence: GitHub