An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/pluck-cms/pluck/issues/83 | third party advisory exploit |
https://github.com/pluck-cms/pluck/issues/91 | third party advisory issue tracking exploit |