Cross-Site Request Forgery Vulnerability in Pluck by Pluck CMS
CVE-2019-9052
6.5MEDIUM
What is CVE-2019-9052?
A CSRF vulnerability has been identified in Pluck version 4.7.9-dev1 that allows attackers to delete images through a specifically crafted request. This issue can be exploited by sending a request to the /admin.php?action=deleteimage&var1= endpoint, which can lead to unauthorized image deletions without proper user authentication. It's crucial for users of this version to apply necessary mitigations to safeguard against potential unauthorized actions.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
