An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21564
Reference (s):
- https://github.com/pluck-cms/pluck/issues/83
- https://github.com/pluck-cms/pluck/issues/91