An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.
No PoCs from references.
- https://github.com/0xT11/CVE-POC
- https://github.com/Alyssa-o-Herrera/CVE-2018-7197
- https://github.com/hectorgie/PoC-in-GitHub