Authenticate Remote Code Execution in Pluck CMS
CVE-2023-25828
7.2HIGH
What is CVE-2023-25828?
Pluck CMS is susceptible to an authenticated remote code execution vulnerability via its albums module, which is integral for managing image collections on the site. This vulnerability arises because the module permits uploads of various file types without properly validating file extensions. Consequently, an attacker could upload a maliciously crafted JPEG file containing a PHP web-shell, allowing direct access to execute code on the server. Successful exploitation requires administrator credentials to access the albums module, making it critical for administrators to ensure secure practices are in place to defend against such threats.
Affected Version(s)
pluck-cms 4.7 <= 4.7.16-dev4
