Impact
A weakness exists in the Albums module of Pluck CMS where the function htmlspecialchars_decode can be exploited through a manipulated Info argument. This flaw allows an attacker to inject arbitrary scripts into the output that is rendered in the admin interface, leading to cross‑site scripting in the admin area.
Affected Systems
Pluck CMS installations up to and including version 4.7.21 that include the Albums module are vulnerable. The flaw is present in the core code of the module and no patch is currently available for these versions.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is under 1 %, suggesting low to very low exploitation likelihood at present. The vulnerability is not listed in the CISA KEV catalog, but exploit code is publicly available. The attack vector is remote, as an unauthenticated user can send a crafted request to the album admin endpoint to trigger the flaw.
OpenCVE Enrichment