Cross-Site Request Forgery Vulnerability in Pluck by Pluck CMS
CVE-2019-9052

6.5MEDIUM

Key Information:

Vendor

Pluck-cms

Status
Vendor
CVE Published:
23 February 2019

What is CVE-2019-9052?

A CSRF vulnerability has been identified in Pluck version 4.7.9-dev1 that allows attackers to delete images through a specifically crafted request. This issue can be exploited by sending a request to the /admin.php?action=deleteimage&var1= endpoint, which can lead to unauthorized image deletions without proper user authentication. It's crucial for users of this version to apply necessary mitigations to safeguard against potential unauthorized actions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.