PT-2023-20940 · Pluck Cms · Pluck Cms
Published
2023-06-26
·
Updated
2023-07-05
·
CVE-2023-27082
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pluck CMS versions 4.7.15 through 4.7.16-dev4
Description
The issue is related to a Cross Site Scripting (XSS) vulnerability. It affects the /admin.php endpoint, allowing remote attackers to run arbitrary code via the upload of a crafted html file.
Recommendations
For Pluck CMS versions 4.7.15 through 4.7.16-dev4, consider disabling the upload functionality in the /admin.php endpoint until a patch is available. Restrict access to the /admin.php endpoint to minimize the risk of exploitation. Avoid using the upload feature for html files in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pluck Cms