CVE-2020-29607

HIGH

Pluck CMS <4.7.13 - RCE

Title source: llm

Description

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

Exploits (9)

exploitdb WORKING POC VERIFIED
by Ron Jost · pythonwebappsphp
https://www.exploit-db.com/exploits/49909
nomisec WORKING POC 6 stars
by abbarhissarh · poc
https://github.com/abbarhissarh/CVE-2020-29607
nomisec WORKING POC 6 stars
by ar2o3 · poc
https://github.com/ar2o3/CVE-2020-29607
nomisec WORKING POC 1 stars
by 0xN7y · poc
https://github.com/0xN7y/CVE-2020-29607
nomisec WORKING POC
by estebanzarate · poc
https://github.com/estebanzarate/CVE-2020-29607-Pluck-CMS-4.7.13-Authenticated-File-Upload-RCE-PoC
nomisec WORKING POC
by CaelumIsMe · poc
https://github.com/CaelumIsMe/CVE-2020-29607-POC
nomisec WORKING POC
by Alienfader · poc
https://github.com/Alienfader/CVE-2020-29607
inthewild WORKING POC
poc
https://github.com/0xstarford/cve-2020-29607
inthewild WORKING POC
poc
https://github.com/0xabbarhsf/cve-2020-29607

Scores

CVSS v3 7.2
EPSS 0.7686
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
pluck-cms/pluck < 4.7.13
Published Dec 16, 2020
Tracked Since Feb 18, 2026