Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2966 | Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2 fixes the vulnerability. |
Github GHSA |
GHSA-6h8w-hrfp-pffx | Plenti arbitrary file deletion vulnerability |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 14 Nov 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plenti plenti
|
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:plenti:plenti:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plenti plenti
|
|
| Metrics |
cvssV3_1
|
Fri, 25 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plenti
Plenti plentico |
|
| CPEs | cpe:2.3:a:plenti:plentico:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plenti
Plenti plentico |
|
| Metrics |
ssvc
|
Fri, 25 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2 fixes the vulnerability. | |
| Title | Plenti arbitrary file deletion vulnerability | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-25T13:47:34.600Z
Reserved: 2024-10-14T13:56:34.814Z
Link: CVE-2024-49381
Updated: 2024-10-25T13:25:55.529Z
Status : Analyzed
Published: 2024-10-25T14:15:12.160
Modified: 2024-11-14T23:04:21.637
Link: CVE-2024-49381
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA