Security Advisory
CVE-2018-11331
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.