Remote Code Execution in Pluck CMS by Unauthenticated ZIP Upload
CVE-2019-9050
7.2HIGH
What is CVE-2019-9050?
In Pluck CMS version 4.7.9-dev1, a significant vulnerability exists that permits administrators to execute arbitrary code. This is achieved by exploiting the action=installmodule functionality, whereby an unauthenticated user can upload a ZIP archive. Once uploaded, the contents of the ZIP file are extracted and executed on the server, leading to potential exploitation of the system.