Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component ” /admin.php?action=page.”
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18195
Reference (s):
- https://github.com/pluck-cms/pluck/issues/69

