CVE-2023-25828

Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev1:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev2:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev3:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev4:*:*:*:*:*:*

History

07 Nov 2023, 04:09

Type Values Removed Values Added
Summary Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High) Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)

31 Mar 2023, 13:41

Type Values Removed Values Added
References (MISC) https://www.synopsys.com/blogs/software-security/pluck-cms-vulnerability/ - (MISC) https://www.synopsys.com/blogs/software-security/pluck-cms-vulnerability/ - Patch, Third Party Advisory
First Time Pluck-cms pluck
Pluck-cms
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-434
CPE cpe:2.3:a:pluck-cms:pluck:4.7.16:dev1:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev4:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev2:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:4.7.16:dev3:*:*:*:*:*:*
cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*

27 Mar 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-27 17:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-25828

Mitre link : CVE-2023-25828

CVE.ORG link : CVE-2023-25828


JSON object : View

Products Affected

pluck-cms

  • pluck
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type