Remote Code Execution in Pluck CMS by Unauthenticated ZIP Upload
CVE-2019-9050
7.2HIGH
What is CVE-2019-9050?
In Pluck CMS version 4.7.9-dev1, a significant vulnerability exists that permits administrators to execute arbitrary code. This is achieved by exploiting the action=installmodule functionality, whereby an unauthenticated user can upload a ZIP archive. Once uploaded, the contents of the ZIP file are extracted and executed on the server, leading to potential exploitation of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
