Missing SSL Certificate Validation in Pluck CMS by Pluck
CVE-2021-31747
4.8MEDIUM
What is CVE-2021-31747?
A significant security vulnerability has been identified in Pluck CMS version 4.7.15, where the update_applet.php component fails to perform proper SSL certificate validation. This oversight can allow attackers to exploit this weakness and execute man-in-the-middle attacks, potentially compromising sensitive data exchanged between users and the application. Users are advised to take immediate action to secure their installations against this vulnerability.