Pluck-cms

Pluck

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 17.05.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 05:08:29

Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."

Exploit
  • EPSS 54.22%
  • Veröffentlicht 16.12.2020 15:15:12
  • Zuletzt bearbeitet 16.04.2025 15:15:46

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

Exploit
  • EPSS 3.73%
  • Veröffentlicht 30.09.2020 18:15:24
  • Zuletzt bearbeitet 21.11.2024 05:12:41

An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.

Exploit
  • EPSS 2.65%
  • Veröffentlicht 19.04.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:55

data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 23.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:53

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 23.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:53

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.

Exploit
  • EPSS 0.94%
  • Veröffentlicht 23.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:53

An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installmodule to upload a ZIP archive, which is then extracted and executed.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 23.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:53

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 23.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:52

An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 04.12.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:06

Pluck v4.7.7 allows CSRF via admin.php?action=settings.