Remote Command Execution Vulnerability in Pluck CMS
CVE-2021-27984

8.1HIGH

Key Information:

Vendor

Pluck-cms

Status
Vendor
CVE Published:
10 December 2021

What is CVE-2021-27984?

A vulnerability in the Pluck CMS version 4.7.15 allows for remote command execution through improper handling of uploaded files in the admin background. This could enable an attacker to execute arbitrary commands on the server, potentially compromising the integrity and security of the web application. Users of Pluck CMS are advised to apply the necessary security patches to mitigate the risk associated with this vulnerability. For further details, refer to the GitHub issue page.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.