Lucene search

K
osvGoogleOSV:CVE-2022-27432
HistoryMar 30, 2022 - 12:15 a.m.

CVE-2022-27432

2022-03-3000:15:09
Google
osv.dev
6
cross-site request forgery
pluck cms
account takeover

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

42.8%

A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for OSV:CVE-2022-27432