CVE-2020-29607 EXPLOIT
7.2
HIGH · CVSS 3.1 · EPSS 33.2% (pctl 98)
Patch early
A public exploit exists.
Description
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
Scoring
| CVSS | 7.2 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 33.19% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-12-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| pluck-cms | pluck |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated) | 2021-05-26 |
References
- http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit
- https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-29607.md
- https://github.com/pluck-cms/pluck/issues/96
- http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit
- https://github.com/pluck-cms/pluck/issues/96
→ the Explorer · watch your stack · NVD