CVE-2023-50564 is an arbitrary file upload vulnerability in Pluck-CMS version 4.7.18, specifically in the /inc/modules_install.php component. The vulnerability allows an attacker to upload a crafted ZIP file, which can result in the execution of arbitrary code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone authenticated web exploit consisting of a README and a single Python script, exploit.py. The script targets a Pluck CMS-style administrative panel that supports module installation from ZIP archives. Its purpose is to automate a full exploitation chain: authenticate to the admin panel using a known password, generate a random module name, build a ZIP archive entirely in memory, place a PHP reverse shell file named rev.php inside it, upload that ZIP to the module installation endpoint, and finally trigger the uploaded PHP file via a predictable web path. The exploit’s main capability is authenticated remote code execution through malicious module upload, culminating in a reverse shell. The embedded payload is simple but functional: PHP uses fsockopen() to connect back to an attacker-supplied IP and port, then proc_open() launches /bin/sh -i with its standard streams redirected over the socket. This makes the exploit operational rather than a mere proof of concept. Repository structure is minimal: README.md documents setup and usage in Spanish, while exploit.py contains all exploit logic. The Python code uses requests for HTTP session handling, zipfile and io to create the ZIP in memory, and random/string to generate a unique module directory name. There is no brute force, persistence, privilege escalation, or post-exploitation automation; success depends on valid credentials and the target accepting/installing the uploaded module. The script also assumes the uploaded module becomes reachable under /data/modules/<random_name>/rev.php and treats an HTTP read timeout during triggering as a likely sign that the reverse shell is active.
This repository contains a Python exploit (exploit.py) targeting Pluck CMS v4.7.18 (CVE-2023-50564). The exploit leverages an authenticated module upload vulnerability, allowing an attacker with admin credentials to upload a ZIP file containing a PHP shell. The script automates authentication, ZIP creation, module upload, and payload triggering, resulting in remote code execution. The repository includes a README with usage instructions, a requirements.txt for dependencies (requests, requests-toolbelt), and a LICENSE file. The main entry point is exploit.py, which requires the attacker to supply a PHP shell file. The exploit interacts with three main HTTP endpoints on the target: the login page, the module upload endpoint, and the location where the shell is deployed and executed. The exploit is operational and provides a working RCE vector for authenticated attackers.
This repository contains a Bash script (CVE-2023-50564) and a README.md. The script is an exploit for a Remote Code Execution (RCE) vulnerability in Pluck CMS v4.7.18 (CVE-2023-50564). It automates the process of authenticating to the Pluck CMS admin panel, uploading a malicious PHP reverse shell (downloaded from revshells.com and zipped as a module), and triggering its execution to provide a reverse shell to the attacker's machine. The script requires the attacker to provide the target host, admin password, attacker's IP, and port for the reverse shell. The README.md provides detailed usage instructions, prerequisites, and troubleshooting tips. The exploit targets the Pluck CMS admin interface over HTTP and leverages the module upload functionality to achieve code execution. The main endpoints involved are the login page, module upload page, and the path to the uploaded shell. The exploit is operational and provides a working reverse shell if the attacker has valid admin credentials.
This repository provides a proof-of-concept exploit for CVE-2023-50564, a vulnerability in Pluck CMS version 4.7.18 that allows unauthorized file uploads via the module installation feature. The repository contains three files: a LICENSE, a README.md with detailed usage instructions, and the main exploit script 'poc.py'. The exploit is written in Python and requires the user to supply a ZIP file containing a PHP shell (such as pentestmonkey's php-reverse-shell). The script logs into the target Pluck CMS instance, uploads the malicious ZIP file via the vulnerable module installation endpoint, and then accesses the uploaded shell to achieve remote command execution. The exploit targets web servers running Pluck CMS 4.7.18 and requires valid login credentials. The main attack vector is network-based, exploiting HTTP endpoints for login, file upload, and shell execution. The exploit is a proof-of-concept and demonstrates the vulnerability by enabling arbitrary code execution on the target server.
This repository contains a working exploit for CVE-2023-50564, an authenticated arbitrary file upload vulnerability in Pluck-CMS v4.7.18. The main file, CVE-2023-50564.py, is a Python script that automates the exploitation process. It takes as input the target host, valid user credentials, and the attacker's listener details. The script generates a PHP reverse shell payload, compresses it into a ZIP file, and uploads it to the vulnerable module installation endpoint after authenticating to the CMS. Upon successful upload, the script triggers the payload, resulting in a reverse shell connection to the attacker's machine. The repository is structured simply, with the exploit script, a README providing usage instructions, and a license file. The exploit is operational and provides a real shell if the target is vulnerable and the attacker has valid credentials.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.