Record summary

CVE-2022-26965 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBPluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Ashish KoliNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubSkDevilS/Pluck-Exploitation-by-skdevilsRepository PoCby SkDevilSStars: 0Not analyzed5 files

1.2 MiB

GitHub

PoC details

References

3