First published: Tue Apr 12 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | =4.7.15 |
https://medium.com/@devansh3008/pluck-cms-v4-7-15-csrf-vulnerability-at-delete-page-9fff0309f9c
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-26589 is medium.
The Cross-Site Request Forgery (CSRF) vulnerability in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages by tricking a user into performing unwanted actions on the website without their knowledge or consent.
You can check if your Pluck CMS installation is affected by CVE-2022-26589 by verifying that you are running version 4.7.15.
To fix the Cross-Site Request Forgery (CSRF) vulnerability in Pluck CMS v4.7.15, you should upgrade your installation to a patched version provided by the vendor.
You can find more information about the Cross-Site Request Forgery (CSRF) vulnerability in Pluck CMS v4.7.15 in the references provided: [Medium article](https://medium.com/@devansh3008/pluck-cms-v4-7-15-csrf-vulnerability-at-delete-page-9fff0309f9c) and [OWASP CSRF Guide](https://owasp.org/www-community/attacks/csrf).