jenaye/pligg

jenaye/pligg

Releases0
Stars6
Remote command execution (Authenticated RCE)

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH6.5 MEDIUM

Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Open request.