Cross-Site Request Forgery Vulnerability in Pluck by Pluck CMS
CVE-2019-9052
6.5MEDIUM
What is CVE-2019-9052?
A CSRF vulnerability has been identified in Pluck version 4.7.9-dev1 that allows attackers to delete images through a specifically crafted request. This issue can be exploited by sending a request to the /admin.php?action=deleteimage&var1= endpoint, which can lead to unauthorized image deletions without proper user authentication. It's crucial for users of this version to apply necessary mitigations to safeguard against potential unauthorized actions.