CRITICAL🇵🇱 Wersja polska

CVE-2024-43042

CVSS 9.8v3.1pub. 2024-08-16upd. 2025-03-19

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

🤖 AI Analysis
How it works

The application does not implement any security mechanisms limiting multiple failed authentication attempts (CWE-307). An attacker can automatically send login requests with different password combinations without risking account lockout or process slowdown. As a result, a full brute force attack on the CMS administration panel is possible.

Impact

A successful brute force attack can lead to administrator account takeover, which consequently enables the attacker to have full control over the CMS system — including content modification, malicious file upload, or further server compromise.

Mitigation & patch

Apply patches available from the vendor according to the references provided. As additional remedial measures, it is recommended to implement external login attempt restriction mechanisms (e.g., rate limiting at the firewall or web server level), use strong and unique administrator passwords, and consider restricting access to the login panel at the IP address level.

Who is affected

Pluck CMS version 4.7.18

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Pluck Cms Pluck

    APP
    Pluck-Cms
    4.7.18
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-31746CRITICAL9.8PL ✓same product

Zip Slip w Pluck CMS — path traversal i zdalne wykonanie kodu

CVE-2020-20951CRITICAL9.8PL ✓same product

RCE w Pluck CMS poprzez niebezpieczne przesyłanie plików

CVE-2019-11344CRITICAL9.8PL ✓same product

Pluck CMS 4.7.8 — zdalne wykonanie kodu przez upload pliku .htaccess

CVE-2018-11736CRITICAL9.8PL ✓same product

Pluck CMS — upload i wykonanie dowolnego kodu PHP przez fałszywy typ MIME

CVE-2018-11331CRITICAL9.8PL ✓same product

Pluck CMS — zdalne wykonanie kodu PHP przez upload pliku .phtml/.htaccess