Record summary

CVE-2024-49380 has a selected CVSS score of 8.9 (high); EIP currently links 1 Nuclei template.

Description

Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 29, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 25, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE ListBefore 0.7.2affected
CVE List< 0.7.2affected

github.com/plentico/plenti

Browse Go / github.com/plentico/plenti
GitHub AdvisoryBefore 0.7.2 · Fixed in 0.7.2affected

Nuclei templates

1
ProjectDiscoveryCRITICALPlenti < v0.7.2 - OS Command InjectionCVSS 9.8

Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.

Impact

Unauthenticated attackers can write arbitrary files to the server, potentially achieving remote code execution.

Remediation

Update Plenti to version 0.7.2 or later.

WeaknessesCWE-78
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024plentirceinjectionintrusivevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: title:"Plenti"

Source: ProjectDiscovery

References

5