Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
References
Link Resource
https://github.com/pluck-cms/pluck/issues/63 Exploit Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-12T16:00:00

Updated: 2018-09-12T15:57:01

Reserved: 2018-09-08T00:00:00


Link: CVE-2018-16729

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-12T16:29:03.350

Modified: 2018-11-09T16:17:12.583


Link: CVE-2018-16729

JSON object: View

cve-icon Redhat Information

No data.

CWE