CVE-2024-46609

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

History

28 Apr 2025, 18:33

Type Values Removed Values Added
References () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - Exploit, Third Party Advisory
References () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Exploit, Third Party Advisory
First Time Thecosy
Thecosy icecms
CPE cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

27 Sep 2024, 16:35

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2025-04-28 18:33


NVD link : CVE-2024-46609

Mitre link : CVE-2024-46609

CVE.ORG link : CVE-2024-46609


JSON object : View

Products Affected

thecosy

  • icecms
CWE
CWE-284

Improper Access Control