First published: Mon May 21 2018(Updated: )
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | <4.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-11330.
The severity of CVE-2018-11330 is medium with a score of 4.8.
The affected software is Pluck CMS version up to 4.7.6.
The CWE ID for this vulnerability is CWE-79.
To fix CVE-2018-11330, update Pluck CMS to version 4.7.6 or higher.