Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-46610

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-46610
  • Thecosy » Icecms » Version: 1.0.0
    cpe:2.3:a:thecosy:icecms:1.0.0
  • Thecosy » Icecms » Version: 2.0.1
    cpe:2.3:a:thecosy:icecms:2.0.1


Contact Us

Shodan ® - All rights reserved