Security Advisory

CVE-2018-7197

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-02-18 03:00:00
Last updated 2024-08-05 06:24:11
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.