CVE-2024-46609

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*

History

28 Apr 2025, 18:33

Type Values Removed Values Added
First Time Thecosy
Thecosy icecms
CPE cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:*
References () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46609.md - Exploit, Third Party Advisory
References () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Exploit, Third Party Advisory

27 Sep 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.5

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Un problema de control de acceso en la función CheckVip en UserController.java de IceCMS v3.4.7 y anteriores permite a atacantes no autenticados acceder y devolver toda la información del usuario, incluidas las contraseñas.

25 Sep 2024, 01:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-284

25 Sep 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2025-04-28 18:33


NVD link : CVE-2024-46609

Mitre link : CVE-2024-46609

CVE.ORG link : CVE-2024-46609


JSON object : View

Products Affected

thecosy

  • icecms
CWE
CWE-284

Improper Access Control