CVE-2024-46609

HIGH

IceCMS < 3.4.7 - Unauthenticated Information Disclosure via CheckVip Function

Title source: llm
STIX 2.1

Description

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
thecosy/icecms < 3.4.7
Published Sep 25, 2024
Tracked Since Feb 18, 2026