ZeroHour

CVE-2024-46607

PoC
CVSS 3.1
7.6 high
EPSS
<1%p43
Published
()
Modified
Description

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.

Vendors
thecosy
Products
icecms
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.