LiveActive security incident?Get immediate response
CVE Record

CVE-2020-18198: Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and...

Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2020-18198 describes a CSRF issue in Pluck CMS v4.7.9. A remote attacker may be able to abuse the admin images component to trigger arbitrary code execution or delete specific images. The public record does not provide CVSS scoring, a named patch, or evidence of active exploitation.

Executive priority

Treat this as high priority where Pluck CMS v4.7.9 is used, especially for public sites. The stated impact includes arbitrary code execution, but evidence is thin; prioritize verification, exposure reduction, and vendor-confirmed remediation.

Technical view

The CVE description identifies a CSRF flaw involving /admin.php?action=images in Pluck CMS v4.7.9. Impact is stated as arbitrary code execution and deletion of specific images. The available source bundle does not describe prerequisites, affected version ranges beyond v4.7.9, exploit maturity, or remediation details.

Likely exposure

Exposure is most likely on public or internally reachable sites running Pluck CMS v4.7.9 with an accessible administrative image-management function. The supplied affected-product metadata is incomplete, so asset validation should rely on installed software evidence, not CPE matching.

Exploitation context

CISA KEV is false in the provided bundle, and no cited source confirms active exploitation. Because this is described as CSRF, practical abuse may depend on an administrator’s authenticated browser session, but the public bundle does not detail exact prerequisites.

Researcher notes

The source record is sparse: no CVSS, CWE, CPEs, exploit status, or fixed version are provided. The strongest grounded facts are the product/version, CSRF class, affected admin images path, and stated impacts. Avoid assuming broader Pluck CMS version exposure without additional evidence.

Mitigation direction

  • Inventory Pluck CMS deployments and identify any v4.7.9 instances.
  • Check Pluck CMS project guidance and releases for a confirmed fix.
  • Restrict access to admin.php to trusted networks or VPN.
  • Reduce unnecessary admin privileges until remediation is confirmed.
  • Back up images and site content before remediation work.

Validation and detection

  • Confirm installed Pluck CMS version from application files or admin metadata.
  • Verify whether the admin images component is enabled and reachable.
  • Review web logs for unusual admin image-management activity.
  • Check whether administrative access is internet-exposed.
  • Track vendor issue status before declaring remediation complete.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-18198 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.