Show filters
45 Total Results
Displaying 11-20 of 45
Sort by:
Attacker Value
Unknown
CVE-2023-25828
Disclosure Date: March 27, 2023 (last updated November 08, 2023)
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)
0
Attacker Value
Unknown
CVE-2022-26589
Disclosure Date: April 13, 2022 (last updated October 07, 2023)
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
0
Attacker Value
Unknown
CVE-2022-27432
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
0
Attacker Value
Unknown
CVE-2022-26965
Disclosure Date: March 18, 2022 (last updated October 07, 2023)
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
0
Attacker Value
Unknown
CVE-2021-31747
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-middle attacks.
0
Attacker Value
Unknown
CVE-2021-27984
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
0
Attacker Value
Unknown
CVE-2021-31746
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-31745
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
0
Attacker Value
Unknown
CVE-2020-24740
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
0
Attacker Value
Unknown
CVE-2020-20951
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
0