Cross-Site Request Forgery Vulnerability in Pluck CMS from Pluck
CVE-2022-26589

6.5MEDIUM

Key Information:

Vendor

Pluck-cms

Status
Vendor
CVE Published:
13 April 2022

What is CVE-2022-26589?

A vulnerability in Pluck CMS v4.7.15 allows attackers to exploit a Cross-Site Request Forgery (CSRF) attack to delete arbitrary pages. By exploiting this security loophole, unauthorized individuals could manipulate user sessions and force actions without the user's consent. Organizations using this version should prioritize updates to mitigate the risk of unwanted data loss and ensure the integrity of their content management system.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.