Cross-Site Scripting Vulnerability in Pluxml by Pluxml
CVE-2022-25020
Key Information:
Badges
What is CVE-2022-25020?
Pluxml v5.8.7 is compromised by a cross-site scripting (XSS) vulnerability that permits attackers to execute arbitrary web scripts or HTML. The exploit can be activated through a specially crafted payload embedded in the thumbnail path of a blog post, potentially allowing unauthorized actions or data retrieval from users viewing affected content. Users are urged to examine their setups for vulnerable versions and to apply any necessary updates to safeguard against this risk.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
