CVE-2020-29607 is a high-severity file upload restriction bypass vulnerability affecting Pluck CMS versions prior to 4.7.13, which allows an authenticated administrator to upload malicious files through the "manage files" functionality. With a CVSS score of 7.2 (High), this flaw enables an attacker with high privileges to achieve remote code execution, potentially leading to full compromise of the host system with low attack complexity. Although not listed in CISA's Known Exploited Vulnerabilities catalog, a public exploit for authenticated remote code execution is available on ExploitDB, and the vulnerability is on the "Hot List: Active" indicating ongoing attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7.13CPE matchmatch criteria | cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.