PT-2023-27661 · Thecosy · Thecosy Icecms

·

CVE-2023-40833

·

Published

2023-10-12

·

Updated

2023-12-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thecosy IceCMS version 1.0.0
Description The issue allows a remote attacker to gain privileges. This is achieved via the Id and key parameters in the getCosSetting function.
Recommendations For Thecosy IceCMS version 1.0.0, consider restricting access to the getCosSetting function until a patch is available. Avoid using the Id and key parameters in this function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-40833

Affected Products

Thecosy Icecms