CVE-2025-46099 - Pluck CMS Remote Code Execution Vulnerability
CVE ID : CVE-2025-46099
Published : July 23, 2025, 2:15 p.m. | 3 hours, 25 minutes ago
Description : In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 23, 2025, 2:15 p.m. | 3 hours, 25 minutes ago
Description : In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...