An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
History

Fri, 27 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 24 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Icecms Project
Icecms Project icecms
Weaknesses CWE-284
CPEs cpe:2.3:a:icecms_project:icecms:3.4.7:*:*:*:*:*:*:*
Vendors & Products Icecms Project
Icecms Project icecms
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 20:00:00 +0000

Type Values Removed Values Added
Description An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-24T00:00:00

Updated: 2024-09-27T15:25:37.781Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46609

cve-icon Vulnrichment

Updated: 2024-09-24T20:09:12.365Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T01:15:44.447

Modified: 2024-09-27T16:35:03.627

Link: CVE-2024-46609

cve-icon Redhat

No data.