CVE-2020-29607
Summary
| CVE | CVE-2020-29607 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-16 15:15:00 UTC |
| Updated | 2022-02-07 21:36:00 UTC |
| Description | A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pluck CMS 4.7.13 Remote Shell Upload ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Exploits/CVE-2020-29607-Exploit at main · Hacker5preme/Exploits · GitHub | MISC | github.com | |
| Remote Code Execution via File Upload Restriction Bypass · Issue #96 · pluck-cms/pluck · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.