Remote Code Execution via Image Upload in Pluck CMS
CVE-2018-11736
9.8CRITICAL
What is CVE-2018-11736?
An issue in Pluck CMS prior to version 4.7.7-dev2 enables remote attackers to upload and execute arbitrary PHP code by exploiting the incorrect handling of .htaccess files disguised as image/jpeg content. This vulnerability poses significant security risks, allowing unauthorized access and execution of malicious scripts on the server.