Closed Lilc1 closed 5 years ago
You have to first be logged in to pluck. This is not possible when you are not logged in. when you know the password you can simple browse the file upload page.
Could you please test the latest dev release 4.7.10-dev4? https://github.com/pluck-cms/pluck/releases/tag/4.7.10-dev4
Have you retested with the latest dev version?
This problem was found in Pluck v4.7.10-dev2. This CSRF vulnerability can add a txt file via /admin.php?action=abc. poc
Verification The uploaded file is stored in the /files/ directory.