Record summary

CVE-2022-27432 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account TakeoverExploitDB exploitby Devansh BordiaNot analyzed1 file
ExploitDB

PoC details

References

3