CVE-2023-6758

MEDIUM

Thecosy IceCMS 2.0.1 - Improper Access Control in PlanetCommentList API

Title source: llm
STIX 2.1

Description

A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247886 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.247886
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.247886
Exploit, Third Party Advisory exploit
http://124.71.147.32:8082/IceCMS4.html

Scores

CVSS v3 5.3
EPSS 0.0074
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-284
Status published
Products (1)
thecosy/icecms 2.0.1
Published Dec 13, 2023
Tracked Since Feb 18, 2026