Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
History

Tue, 24 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Thecosy
Thecosy icecms
Weaknesses CWE-284
CPEs cpe:2.3:a:thecosy:icecms:3.4.7:*:*:*:*:*:*:*
Vendors & Products Thecosy
Thecosy icecms
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-24T00:00:00

Updated: 2024-09-24T20:05:31.859Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46607

cve-icon Vulnrichment

Updated: 2024-09-24T19:59:22.430Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T01:15:44.390

Modified: 2024-09-26T13:32:02.803

Link: CVE-2024-46607

cve-icon Redhat

No data.