CVE-2021-47722
LOWZucchetti Axess CLOKI Access Control 1.64 - CSRF
Title source: llmDescription
Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.
Exploits (1)
References (4)
Scores
CVSS v3
3.5
EPSS
0.0001
EPSS Percentile
0.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-352
Status
draft
Timeline
Published
Dec 23, 2025
Tracked Since
Feb 18, 2026