CVE-2024-49380
Plenti arbitrary file write vulnerability
Record summary
CVE-2024-49380 has a selected CVSS score of 8.9 (high); EIP currently links 1 Nuclei template.
Description
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 29, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 25, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
plentiBrowse plenti / plenti | VulnCheck | Version data not supplied | |
plenticoBrowse plenti / plenticoDefault status: unknown | CVE List | Before 0.7.2 | affected |
plentiBrowse plentico / plenti | CVE List | < 0.7.2 | affected |
github.com/plentico/plentiBrowse Go / github.com/plentico/plenti | GitHub Advisory | Before 0.7.2 · Fixed in 0.7.2 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALPlenti < v0.7.2 - OS Command InjectionCVSS 9.8
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.
Impact
Unauthenticated attackers can write arbitrary files to the server, potentially achieving remote code execution.
Remediation
Update Plenti to version 0.7.2 or later.
Source: ProjectDiscovery