An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md | Exploit Third Party Advisory |
https://github.com/Thecosy/iceCMS?tab=readme-ov-file | Exploit Third Party Advisory |
Configurations
History
28 Apr 2025, 18:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - Exploit, Third Party Advisory | |
References | () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Exploit, Third Party Advisory | |
First Time |
Thecosy
Thecosy icecms |
|
CPE | cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:* |
25 Sep 2024, 01:36
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-25 01:15
Updated : 2025-04-28 18:33
NVD link : CVE-2024-46609
Mitre link : CVE-2024-46609
JSON object : View
Products Affected
thecosy
- icecms
CWE
No CWE.