Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55r3-2rh8-427f

Опубликовано: 23 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
7 месяцев назад

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

EPSS

Процентиль: 20%
0.00063
Низкий

7.1 High

CVSS3

Дефекты

CWE-434