PT-2024-32076 · Icecms · Icecms

Lunax0

·

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2024-46612

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IceCMS versions 3.4.7 and earlier
Description The issue allows an attacker to forge JWT authentication information due to a hardcoded JWT key.
Recommendations For IceCMS versions 3.4.7 and earlier, update to a version that does not contain the hardcoded JWT key to prevent attackers from forging JWT authentication information. As a temporary workaround, consider regenerating and updating the JWT key to a secure, non-hardcoded value until a patched version is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-46612

Affected Products

Icecms