CVE-2021-47722

LOW

Zucchetti Axess CLOKI Access Control 1.64 - CSRF

Title source: llm

Description

Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/50595

Scores

CVSS v3 3.5
EPSS 0.0001
EPSS Percentile 0.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-352
Status draft

Timeline

Published Dec 23, 2025
Tracked Since Feb 18, 2026