Логотип exploitDog
bind:CVE-2025-46099
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-46099

Количество 2

Количество 2

nvd логотип

CVE-2025-46099

7 месяцев назад

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-55r3-2rh8-427f

7 месяцев назад

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-46099

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

CVSS3: 7.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-55r3-2rh8-427f

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.

CVSS3: 7.1
0%
Низкий
7 месяцев назад

Уязвимостей на страницу