3.7

CVE-2023-6467

Exploit

Thecosy IceCMS Comment Like improper enforcement of a single, unique action

A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /Websquare/likeClickComment/ of the component Comment Like Handler. The manipulation leads to improper enforcement of a single, unique action. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-246617 was assigned to this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ThecosyIcecms Version2.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.62% 0.448
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
cna@vuldb.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
cna@vuldb.com 2.1 3.9 2.9
AV:N/AC:H/Au:S/C:N/I:P/A:N
CWE-837 Improper Enforcement of a Single, Unique Action

The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction.

http://39.106.130.187/wenjian/2.html
Third Party Advisory
Exploit
https://vuldb.com/?ctiid.246617
Third Party Advisory
Permissions Required
https://vuldb.com/?id.246617
Third Party Advisory