nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27432 CVE-2022-27432
HIGH
ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Takeover
Record summary
CVE-2022-27432 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account TakeoverExploitDB exploitby Devansh BordiaNot analyzed1 file
References
3owasp.org
https://owasp.org/www-community/attacks/csrf exploit-db.com
https://www.exploit-db.com/exploits/50831