CVE-2024-46609

A

n access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

History

28 Apr 2025, 18:33

Type Values Removed Values Added
First Time Thecosy icecms
Thecosy
References () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - Exploit, Third Party Advisory
References () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Exploit, Third Party Advisory
CPE cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

27 Sep 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.5

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Un problema de control de acceso en la función CheckVip en UserController.java de IceCMS v3.4.7 y anteriores permite a atacantes no autenticados acceder y devolver toda la información del usuario, incluidas las contraseñas.

25 Sep 2024, 01:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-284

25 Sep 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2025-04-28 18:33


NVD link : CVE-2024-46609

Mitre link : CVE-2024-46609

CVE.ORG link : CVE-2024-46609


JSON object : View

Products Affected
CWE
CWE-284

Improper Access Control