Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users into loading the page. | |
| Title | Zucchetti Axess CLOKI Access Control 1.64 Cross-Site Request Forgery | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-23T20:05:03.518Z
Reserved: 2025-12-07T14:25:05.584Z
Link: CVE-2021-47722
Updated: 2025-12-23T20:04:53.675Z
Status : Received
Published: 2025-12-23T20:15:44.660
Modified: 2025-12-23T20:15:44.660
Link: CVE-2021-47722
No data.
OpenCVE Enrichment
No data.