Filtered by vendor Icecms Project
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-46609 | 1 Icecms Project | 1 Icecms | 2024-09-27 | 7.5 High |
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords | ||||
CVE-2024-46612 | 1 Icecms Project | 1 Icecms | 2024-09-26 | 9.8 Critical |
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. |
Page 1 of 1.