Описание
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
Ссылки
- Broken Link
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pluck-cms:pluck:4.7.20:dev:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00063
Низкий
7.2 High
CVSS3
7.1 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.1
github
7 месяцев назад
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
EPSS
Процентиль: 20%
0.00063
Низкий
7.2 High
CVSS3
7.1 High
CVSS3
Дефекты
CWE-434