CVE-2024-46609

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

History

28 Apr 2025, 18:33

Type Values Removed Values Added
References () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - Exploit, Third Party Advisory
References () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Exploit, Third Party Advisory
First Time Thecosy
Thecosy icecms
CPE cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

25 Sep 2024, 01:36

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2025-04-28 18:33


NVD link : CVE-2024-46609

Mitre link : CVE-2024-46609


JSON object : View

Products Affected

thecosy

  • icecms
CWE

No CWE.