Plenti是Plentico开源的一个静态站点生成器。 Plenti 0.7.2之前版本存在注入漏洞,该漏洞源于当用户运行其网站时,/postLocal端点可被利用进行任意文件写入,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-49380.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet