CVE-2018-11331

An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
References
Link Resource
https://github.com/pluck-cms/pluck/issues/58 Issue Tracking Patch Third Party Advisory
https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*

Information

Published : 2018-05-21 14:29

Updated : 2018-06-22 06:36


NVD link : CVE-2018-11331

Mitre link : CVE-2018-11331


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

Advertisement

dedicated server usa

Products Affected

pluck-cms

  • pluck