CVE-2024-49380 is an arbitrary file write vulnerability affecting Plenti, a static site generator, in versions prior to 0.7.2. This flaw in the /postLocal endpoint can lead to Remote Code Execution when a user serves their website. Rated with a CVSS score of 7.5 (HIGH), it has a low attack complexity and does not require user interaction or privileges. While not yet in the KEV catalog, Nuclei templates for OS Command Injection exist, indicating potential for exploitation, though there is no public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.7.2CPE matchmatch criteria | cpe:2.3:a:plenti:plenti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.