
Proof-of-concept for CVE-2021-45007, a CSRF vulnerability in Plesk Obsidian 18.0.37, demonstrating request submission without CSRF token protection.
#Cross-Site Request Forgery
Affected product and version: Plesk Obsidian 18.0.37
Severity: High
Impact: Submit requests with attacker information
Description: CSRF could let the attacker to submit new requests because there isn’t any CSRF_token protection sent with requests to server.
Steps to reproduce:




