CSRF Vulnerability in Pluck CMS by Pluck
CVE-2019-9048
6.5MEDIUM
What is CVE-2019-9048?
A Cross-Site Request Forgery (CSRF) vulnerability exists in Pluck CMS 4.7.9-dev1, allowing a remote attacker to delete themes through a crafted request to admin functionality. This issue arises due to improper validation of user requests, making it possible for malicious entities to manipulate site configurations without the user's consent.