CVE-2023-50564

HIGH

Pluck - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.

Exploits (8)

nomisec WORKING POC 19 stars
by Rai2en · poc
https://github.com/Rai2en/CVE-2023-50564_Pluck-v4.7.18_PoC
nomisec WORKING POC 3 stars
by thefizzyfish · poc
https://github.com/thefizzyfish/CVE-2023-50564-pluck
nomisec WORKING POC 1 stars
by xpltive · poc
https://github.com/xpltive/CVE-2023-50564
nomisec WORKING POC 1 stars
by Mrterrestrial · poc
https://github.com/Mrterrestrial/CVE-2023-50564
nomisec WORKING POC
by glynzr · poc
https://github.com/glynzr/CVE-2023-50564
nomisec WORKING POC
by 0xDTC · poc
https://github.com/0xDTC/Pluck-CMS-v4.7.18-Remote-Code-Execution-CVE-2023-50564
nomisec WORKING POC
by rwexecute · poc
https://github.com/rwexecute/CVE-2023-50564
nomisec WORKING POC
by ipuig · poc
https://github.com/ipuig/CVE-2023-50564

Scores

CVSS v3 8.8
EPSS 0.3522
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
pluck-cms/pluck 4.7.18
Published Dec 14, 2023
Tracked Since Feb 18, 2026