Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

F1Sh1001

#18987of 53,638
14.1Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2021-10562
9.8
2021-05-18
Pluck · Pluck · CVE-2020-20951
Name of the Vulnerable Software and Affected Versions: Pluck version 4.7.10-dev2 Description: A remote command execution issue exists in the admin background when uploading files. Recommendations: For Pluck version 4.7.10-dev2, as a temporary workaround, consider restricting file uploads in the admin background until a patch is available.
PT-2021-11069
4.3
2021-05-18
Pluck · Pluck · CVE-2020-24740
Name of the Vulnerable Software and Affected Versions: Pluck version 4.7.10-dev2 Description: An issue was discovered that allows a CSRF vulnerability, enabling the editing of pages via the "/admin.php?action=editpage" API endpoint. This issue can potentially be exploited to modify pages without proper authorization. Recommendations: For Pluck version 4.7.10-dev2, as a temporary workaround, consider disabling the editpage functionality in the /admin.php?action=editpage endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.