PT-2023-20941 · Pluck Cms · Pluck Cms

Published

2023-06-22

·

Updated

2023-06-30

·

CVE-2023-27083

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pluck CMS versions 4.7.15 through 4.7.16-dev5
Description A remote code execution issue was found in the /admin.php file of Pluck CMS, allowing attackers to execute arbitrary code through the manage file functionality.
Recommendations For Pluck CMS versions 4.7.15 through 4.7.16-dev5, consider disabling the manage file functionality in /admin.php until a patch is available. Restrict access to the /admin.php file to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-27083

Affected Products

Pluck Cms