VYPR
High severity7.2NVD Advisory· Published Dec 16, 2020· Updated Jun 17, 2026

CVE-2020-29607

CVE-2020-29607

Description

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Pluck/Pluck2 versions
    cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pluck-cms:pluck:*:*:*:*:*:*:*:*range: <4.7.13
    • (no CPE)range: <4.7.13
  • Pluck CMS/Pluck CMSdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.