vendor:
pluck
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
RCE
Not provided
CWE
Product Name: pluck
Affected Version From: 4.7.18
Affected Version To: 4.7.18
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Linux
2023
Pluck v4.7.18 – Remote Code Execution (RCE)
The Pluck CMS v4.7.18 is vulnerable to remote code execution (RCE) due to improper handling of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of Pluck CMS and apply any patches or security updates released by the vendor.