Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-27432. PoCs published by Devansh Bordia.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in ICEHRM 31.0.0.OS, allowing an attacker to change a user's password via a crafted HTML form without requiring a CSRF token. The PoC intercepts a GET request to the password change endpoint and automates the attack via a malicious HTML page.
Description
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in ICEHRM 31.0.0.OS, allowing an attacker to change a user's password via a crafted HTML form without requiring a CSRF token. The PoC intercepts a GET request to the password change endpoint and automates the attack via a malicious HTML page.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H