CVE-2018-11331

CRITICAL

Pluck < 4.7.6 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.

References (2)

Core 2
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/pluck-cms/pluck/issues/58

Scores

CVSS v3 9.8
EPSS 0.0074
EPSS Percentile 73.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
pluck-cms/pluck < 4.7.6
Published May 21, 2018
Tracked Since Feb 18, 2026