Description

Multiple cross-site scripting (XSS) vulnerabilities exist in Pluck CMS version 4.5.2. Various parameters across the application fail to properly encode user input before rendering it in HTML responses.

Impact

Attackers can inject malicious JavaScript code that executes in the browsers of other users, enabling session hijacking, credential theft, and potential administrative access.

Solution

Upgrade to the latest version of Pluck CMS.

References