Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Thecosy
Thecosy icecms |
|
Weaknesses | CWE-284 | |
CPEs | cpe:2.3:a:thecosy:icecms:3.4.7:*:*:*:*:*:*:* | |
Vendors & Products |
Thecosy
Thecosy icecms |
|
Metrics |
cvssV3_1
|
Tue, 24 Sep 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-24T00:00:00
Updated: 2024-09-24T20:05:31.859Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46607
Vulnrichment
Updated: 2024-09-24T19:59:22.430Z
NVD
Status : Awaiting Analysis
Published: 2024-09-25T01:15:44.390
Modified: 2024-09-26T13:32:02.803
Link: CVE-2024-46607
Redhat
No data.