CVE-2018-7197
18.02.2018, 03:29
An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
Vendor | Product | Version |
---|---|---|
pluck-cms | pluck | 𝑥 ≤ 4.7.4 |
𝑥
= Vulnerable software versions