CVE-2023-50564
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
- Affected products
- Pluck Cms
- Pluck-cms Pluck
- = 4.7.18
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 29.1% (98th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-12-14
CVE-2023-50564 at NVD
10 known exploits for CVE-2023-50564
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck
Exploit for Unrestricted Upload of File with Dangerous Type in Pluck-Cms Pluck