CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.8. It may be remotely exploitable.
CVE
CVE-2023-27082
Severity
MEDIUM
CVSS
4.8
EPSS
0.59%
Original NVD Description
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
Related CVEs
Other vulnerabilities affecting the same vendor(s)