{"api_version":"1","generated_at":"2026-07-23T02:55:13+00:00","cve":"CVE-2018-11331","urls":{"html":"https://cve.report/CVE-2018-11331","api":"https://cve.report/api/cve/CVE-2018-11331.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-11331","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-11331"},"summary":{"title":"CVE-2018-11331","description":"An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-05-21 21:29:00","updated_at":"2018-06-22 13:36:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://github.com/pluck-cms/pluck/issues/58","name":"https://github.com/pluck-cms/pluck/issues/58","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Xss & file upload vuln. Please advise.  · Issue #58 · pluck-cms/pluck · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e","name":"https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"bugfix for XSS and backdoor file upload found by s7acktrac3 issue #58 · pluck-cms/pluck@8f6541e · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-11331","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11331","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"11331","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pluck-cms","cpe5":"pluck","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"11331","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pluck-cms","cpe5":"pluck","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-11331","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/pluck-cms/pluck/issues/58","refsource":"MISC","url":"https://github.com/pluck-cms/pluck/issues/58"},{"name":"https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e","refsource":"MISC","url":"https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e"}]}},"nvd":{"publishedDate":"2018-05-21 21:29:00","lastModifiedDate":"2018-06-22 13:36:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*","versionEndExcluding":"4.7.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"11331","Ordinal":"127808","Title":"CVE-2018-11331","CVE":"CVE-2018-11331","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"11331","Ordinal":"1","NoteData":"An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"11331","Ordinal":"2","NoteData":"2018-05-21","Type":"Other","Title":"Published"}]}}}