CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
- Affected products
- Pluck Cms
- Pluck-cms Pluck
- < 4.7.13
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 33.2% (98th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2020-12-16
CVE-2020-29607 at NVD
11 known exploits for CVE-2020-29607
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
CVE-2020-29607-POC
CVE-2020-29607-Pluck-CMS-4.7.13-Authenticated-File-Upload-RCE-PoC
CVE-2020-29607
CVE-2020-29607
CVE-2020-29607
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Pluck CMS 4.7.13 Remote Shell Upload
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated) Exploit
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)