First published: Fri Dec 10 2021(Updated: )
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | =4.7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The title of CVE-2021-31746 is 'Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.'
The severity level of CVE-2021-31746 is critical with a score of 9.8.
Pluck-CMS Pluck version 4.7.15 is affected by CVE-2021-31746.
CVE-2021-31746 allows an attacker to perform directory traversal and potentially execute arbitrary code.
Yes, you can find more information about CVE-2021-31746 at the following link: [https://github.com/pluck-cms/pluck/issues/100](https://github.com/pluck-cms/pluck/issues/100)