Authenticate Remote Code Execution in Pluck CMS
CVE-2023-25828

7.2HIGH

Key Information:

Vendor

Pluck

Status
Vendor
CVE Published:
27 March 2023

What is CVE-2023-25828?

Pluck CMS is susceptible to an authenticated remote code execution vulnerability via its albums module, which is integral for managing image collections on the site. This vulnerability arises because the module permits uploads of various file types without properly validating file extensions. Consequently, an attacker could upload a maliciously crafted JPEG file containing a PHP web-shell, allowing direct access to execute code on the server. Successful exploitation requires administrator credentials to access the albums module, making it critical for administrators to ensure secure practices are in place to defend against such threats.

Affected Version(s)

pluck-cms 4.7 <= 4.7.16-dev4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.