nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-26965 CVE-2022-26965
HIGH
Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2022-26965 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Proofs of concept
2Catalogued exploits
ExploitDBPluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Ashish KoliNot analyzed1 file
Repository PoCs
GitHubSkDevilS/Pluck-Exploitation-by-skdevilsRepository PoCby SkDevilSStars: 0Not analyzed5 files
References
3packetstormsecurity.com
https://packetstormsecurity.com/files/166336/Pluck-CMS-4.7.16-Shell-Upload.html youtu.be
https://youtu.be/sN6J_X4mEbY