Lucene search

K
osvGoogleOSV:CVE-2018-7197
HistoryFeb 18, 2018 - 3:29 a.m.

CVE-2018-7197

2018-02-1803:29:00
Google
osv.dev
3

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.8%

An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.

CPENameOperatorVersion
pluckeq4.7.2
pluckeq4.7
pluckeq4.7.3
pluckeq4.7.4

5.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.8%

Related for OSV:CVE-2018-7197