CVE-2020-29607
HIGH 7.2EPSS 33.2%
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 33.19% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2020-12-16
- Updated
- 2025-04-16
Proof-of-concept exploits (9)
- http://packetstormsecurity.com/files/162785/Pluck-CMS-4.7.13-Remote-Shell-Upload.html
- Hacker5preme/Exploits/tree/main/CVE-2020-29607-Exploit
- 0xAbbarhSF/CVE-2020-296076★ · 2022-06-04
- 0xN7y/CVE-2020-296071★ · 2023-11-24
- Alienfader/CVE-2020-296070★ · 2025-02-12
- ar2o3/CVE-2020-296076★ · 2022-06-04
- CaelumIsMe/CVE-2020-29607-POC
- abbarhissarh/CVE-2020-29607
- estebanzarate/CVE-2020-29607-Pluck-CMS-4.7.13-Authenticated-File-Upload-RCE-PoC