PluXml
cpe:2.3:a:pluxml:pluxml:*:*:*:*:*:*:*
A remote code execution vulnerability has been identified in the PluXml CMS theme editor, specifically within the minify.php file located in the default theme directory under themes/defaut/css/. This vulnerability allows authenticated administrator users to overwrite the minify.php file with arbitrary PHP code via the admin panel, which can then be executed to run system commands.
Exploitation of this vulnerability allows for remote code execution on the server, with the executed code running in the context of the web server user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.