File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/pluck-cms/pluck/issues/86 | patch issue tracking exploit |
https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-20969.md |