A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
References
Link Resource
https://owasp.org/www-community/attacks/csrf Third Party Advisory
https://www.exploit-db.com/exploits/50831 Not Applicable VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-29T23:24:46

Updated: 2022-03-29T23:24:46

Reserved: 2022-03-21T00:00:00


Link: CVE-2022-27432

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-30T00:15:09.490

Modified: 2022-04-05T18:43:08.160


Link: CVE-2022-27432

JSON object: View

cve-icon Redhat Information

No data.

CWE