An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
References
Link Resource
https://github.com/pluck-cms/pluck/commit/8f6541e60c9435e82e9c531a20cb3c218d36976e Patch Third Party Advisory
https://github.com/pluck-cms/pluck/issues/58 Issue Tracking Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:52

Updated: 2022-10-03T16:21:52

Reserved: 2022-10-03T00:00:00


Link: CVE-2018-11331

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-05-21T21:29:00.330

Modified: 2018-06-22T13:36:20.340


Link: CVE-2018-11331

JSON object: View

cve-icon Redhat Information

No data.

CWE