CVE-2024-46609

HIGH

Thecosy Icecms < 3.4.7 - Improper Access Control

Title source: rule
STIX 2.1

Description

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 57.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
thecosy/icecms < 3.4.7
Published Sep 25, 2024
Tracked Since Feb 18, 2026