CyberRota Analysis
AI-GeneratedPluck CMS versions up to 4.7.21 are vulnerable due to a weakness in the htmlspecialchars_decode function within the Albums Module, allowing for remote cross-site scripting (XSS) attacks through manipulated input. Although the severity is rated low, the public availability of the exploit means that organizations using this CMS should prioritize patching or mitigating this vulnerability to protect against potential attacks. Administrators of affected systems should assess their exposure and implement necessary safeguards promptly.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.