PT-2024-32073 · Icecms · Icecms

Lunax0

·

Published

2024-09-24

·

Updated

2025-04-28

·

CVE-2024-46609

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IceCMS versions 3.4.7 and earlier
Description An access control issue in the CheckVip function in UserController.java of IceCMS allows unauthenticated attackers to access and return all user information, including passwords.
Recommendations For IceCMS versions 3.4.7 and earlier, as a temporary workaround, consider disabling the CheckVip function in UserController.java until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-46609

Affected Products

Icecms