PT-2020-15093 · Pluxml · Pluxml

Jadacheng

·

Published

2020-10-02

·

Updated

2020-10-08

·

CVE-2020-18185

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PluXml version 5.7
Description The issue allows attackers to execute arbitrary PHP code by modifying the configuration file in a Linux environment, specifically through the class.plx.admin.php file.
Recommendations For PluXml version 5.7, update the class.plx.admin.php file to prevent modification of the configuration file, or restrict access to this file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18185

Affected Products

Pluxml