{"api_version":"1","generated_at":"2026-07-22T02:11:37+00:00","cve":"CVE-2020-29607","urls":{"html":"https://cve.report/CVE-2020-29607","api":"https://cve.report/api/cve/CVE-2020-29607.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-29607","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-29607"},"summary":{"title":"CVE-2020-29607","description":"A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the \"manage files\" functionality, which may result in remote code execution.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-12-16 15:15:00","updated_at":"2022-02-07 21:36:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html","name":"http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html","refsource":"MISC","tags":[],"title":"Pluck CMS 4.7.13 Remote Shell Upload ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit","name":"https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit","refsource":"MISC","tags":[],"title":"Exploits/CVE-2020-29607-Exploit at main · Hacker5preme/Exploits · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/pluck-cms/pluck/issues/96","name":"https://github.com/pluck-cms/pluck/issues/96","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Remote Code Execution via File Upload Restriction Bypass · Issue #96 · pluck-cms/pluck · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-29607","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29607","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"29607","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pluck-cms","cpe5":"pluck","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"29607","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pluck-cms","cpe5":"pluck","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-29607","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the \"manage files\" functionality, which may result in remote code execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/pluck-cms/pluck/issues/96","refsource":"MISC","name":"https://github.com/pluck-cms/pluck/issues/96"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html","url":"http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html"},{"refsource":"MISC","name":"https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit","url":"https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit"}]}},"nvd":{"publishedDate":"2020-12-16 15:15:00","lastModifiedDate":"2022-02-07 21:36:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*","versionEndExcluding":"4.7.13","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"29607","Ordinal":"192784","Title":"CVE-2020-29607","CVE":"CVE-2020-29607","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"29607","Ordinal":"1","NoteData":"A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the \"manage files\" functionality, which may result in remote code execution.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"29607","Ordinal":"2","NoteData":"2020-12-16","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"29607","Ordinal":"3","NoteData":"2022-01-28","Type":"Other","Title":"Modified"}]}}}