CVE-2024-22636

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pluxml:pluxml:5.8.9:*:*:*:*:*:*:*

History

29 Jan 2024, 15:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:pluxml:pluxml:5.8.9:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Pluxml
Pluxml pluxml
References () https://github.com/capture0x/PluXml-RCE/blob/main/PluXml.txt - () https://github.com/capture0x/PluXml-RCE/blob/main/PluXml.txt - Exploit
Summary
  • (es) Se descubrió que PluXml Blog v5.8.9 contiene una vulnerabilidad de ejecución remota de código (RCE) en la función Static Pages. Esta vulnerabilidad se explota inyectando un payload diseñado en el campo Content.

25 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-25 21:15

Updated : 2024-01-29 15:57


NVD link : CVE-2024-22636

Mitre link : CVE-2024-22636

CVE.ORG link : CVE-2024-22636


JSON object : View

Products Affected

pluxml

  • pluxml