CVE-2022-27432

HIGH

Pluck CMS 4.7.15 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-27432. PoCs published by Devansh Bordia.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in ICEHRM 31.0.0.OS, allowing an attacker to change a user's password via a crafted HTML form without requiring a CSRF token. The PoC intercepts a GET request to the password change endpoint and automates the attack via a malicious HTML page.

Description

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

Exploits (1)

exploitdb WORKING POC
by Devansh Bordia · textwebappsphp
https://www.exploit-db.com/exploits/50831

This exploit demonstrates a CSRF vulnerability in ICEHRM 31.0.0.OS, allowing an attacker to change a user's password via a crafted HTML form without requiring a CSRF token. The PoC intercepts a GET request to the password change endpoint and automates the attack via a malicious HTML page.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ICEHRM 31.0.0.OS
Auth required
Prerequisites: Victim must be authenticated in the same browser session · Attacker must know the victim's current password or use a brute-force approach
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://owasp.org/www-community/attacks/csrf
Not Applicable, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50831

Scores

CVSS v3 8.8
EPSS 0.0055
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
pluck-cms/pluck 4.7.15
Published Mar 30, 2022
Tracked Since Feb 18, 2026