CVE-2020-29607
high · 7.2A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
7.2
CVSS
33.2%
EPSS (exploit prob.)
98th
EPSS percentile
2020-12-16
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| pluck-cms | pluck | < 4.7.13 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit
- https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-29607.md
- https://github.com/pluck-cms/pluck/issues/96
- http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit
- https://github.com/pluck-cms/pluck/issues/96
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-29607