CVE-2023-25828
Last modified
CVE-2023-25828 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High)
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Pluck-Cms | Pluck | < 4.7.16 | — |
| Pluck-Cms | Pluck | 4.7.16 | Dev1 |
References
- https://www.synopsys.com/blogs/software-security/pluck-cms-vulnerability/Patch, Third Party Advisory
- https://www.synopsys.com/blogs/software-security/pluck-cms-vulnerability/Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25828?
How severe is CVE-2023-25828?
How do I fix CVE-2023-25828?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-25822ReportPortal is an AI-powered test automation platform. Prio…6.5
- CVE-2023-25823Gradio is an open-source Python library to build machine lea…9.8
- CVE-2023-25824Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS.…7.5
- CVE-2023-25825ZoneMinder is a free, open source Closed-circuit television …6.1
- CVE-2023-25826Due to insufficient validation of parameters passed to the l…9.8
- CVE-2023-25827 Due to insufficient validation of parameters reflected in e…6.1
- CVE-2023-25829There is an unvalidated redirect vulnerability in Esri Porta…6.1
- CVE-2023-2583Code Injection in GitHub repository jsreport/jsreport prior …10
- CVE-2023-25830There is a reflected XSS vulnerability in Esri Portal for Ar…6.1
- CVE-2023-25831There is a reflected XSS vulnerability in Esri Portal for Ar…6.1
- CVE-2023-25832There is a cross-site-request forgery vulnerability in Esri …8.8
- CVE-2023-25833There is an HTML injection vulnerability in Esri Portal for …5.4
Are you affected by CVE-2023-25828?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
