Cross-Site Request Forgery in Pluck CMS Affecting Pluck 4.7.10-dev2
CVE-2020-24740
4.3MEDIUM
What is CVE-2020-24740?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Pluck CMS version 4.7.10-dev2. This flaw allows an attacker to manipulate authenticated users into submitting unauthorized requests, specifically the action to edit pages via the /admin.php?action=editpage endpoint. Attackers can exploit this vulnerability to make unwanted changes to the affected CMS without the user's consent, highlighting the importance of securing web interfaces against such attacks.