
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Pluck CMS versions 4.7.10-dev2 and 4.7.11 that allows remote command execution via admin.php?action=files. The vulnerability was disclosed in August 2020 and assigned identifier CVE-2020-21564. The vulnerability affects the file management interface in the admin backend of Pluck CMS (MITRE).
The vulnerability exists in the file upload functionality within the admin interface, specifically in /data/inc/file.php line 42. The issue occurs when handling file names like '.htaccess', where the strpos function returns 0, allowing for malicious file uploads. This can be exploited through the management file interface by uploading specially crafted files (GitHub Issue 83).
When successfully exploited, this vulnerability allows an attacker to achieve remote command execution on the affected system. The attacker can upload malicious files and execute arbitrary PHP code on the server, potentially leading to complete system compromise (GitHub Issue 83, GitHub Issue 91).
The vulnerability requires authentication to the admin interface before exploitation. A proof of concept exists demonstrating the attack through a series of steps: uploading a .htaccess file, manipulating it through the trash function, and then uploading shell code to achieve remote code execution (GitHub Issue 91).
Users should upgrade to a version newer than 4.7.11 if available. If upgrading is not possible, administrators should carefully monitor and restrict access to the file management interface in the admin backend (MITRE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."