Cross-Site Request Forgery Vulnerability in Pluck CMS from Pluck
CVE-2022-26589
6.5MEDIUM
What is CVE-2022-26589?
A vulnerability in Pluck CMS v4.7.15 allows attackers to exploit a Cross-Site Request Forgery (CSRF) attack to delete arbitrary pages. By exploiting this security loophole, unauthorized individuals could manipulate user sessions and force actions without the user's consent. Organizations using this version should prioritize updates to mitigate the risk of unwanted data loss and ensure the integrity of their content management system.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
