Vulnerabilities
Vulnerable Software
Pluck-Cms:  Security Vulnerabilities
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-04
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-12-04
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-09-12
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
CVSS Score
9.8
EPSS Score
0.009
Published
2018-06-05
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
CVSS Score
4.8
EPSS Score
0.003
Published
2018-05-21
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
CVSS Score
9.8
EPSS Score
0.008
Published
2018-05-21
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
CVSS Score
6.1
EPSS Score
0.004
Published
2018-02-18
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-03-17
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-03-17
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
CVSS Score
9.8
EPSS Score
0.029
Published
2017-03-17


Contact Us

Shodan ® - All rights reserved