ZeroHour

CVE-2020-29607

PoC ×3
CVSS 3.1
7.2 high
EPSS
33%p98
Published
()
Modified
Description

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

Vendors
pluck-cms
Products
pluck
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.