First published: Tue Mar 29 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | =4.7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-27432.
CVE-2022-27432 has a severity level of high (8.8).
The CSRF vulnerability in Pluck CMS v4.7.15 allows attackers to change the password of any user, leading to account takeover.
Version 4.7.15 of Pluck CMS is affected by this vulnerability.
To mitigate the CSRF vulnerability in Pluck CMS v4.7.15, apply the latest security patches or updates provided by the Pluck CMS developers.