7.6
CVE-2024-46607
- EPSS 0.56%
- Veröffentlicht 25.09.2024 01:15:44
- Zuletzt bearbeitet 28.04.2025 17:09:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.6 | 2.1 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
http://icecms.com
https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md
https://github.com/Thecosy/iceCMS?tab=readme-ov-file