High severity8.8NVD Advisory· Published Mar 30, 2022· Updated Jun 17, 2026
CVE-2022-27432
CVE-2022-27432
Description
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Pluck CMS/Pluck CMSdescription
Patches
Vulnerability mechanics
References
2- owasp.org/www-community/attacks/csrfnvdThird Party Advisory
- www.exploit-db.com/exploits/50831nvdNot ApplicableVDB Entry
News mentions
0No linked articles in our index yet.