First published: Tue Jul 16 2019(Updated: )
PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to upload a php file. The fixed version is: after commit 09f0ab871bf633973cfd9fc4fe59d4a912397cf8.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | <=4.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-1010062.
The severity of CVE-2019-1010062 is critical (9.8).
The impact of CVE-2019-1010062 is the ability to get a webshell.
CVE-2019-1010062 can be exploited by modifying the MIME type on an HTTP request to upload a PHP file.
CVE-2019-1010062 can be fixed by updating to a version after commit 09f0ab871.