CVE-2024-46607

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/09/2024
Last modified:
28/04/2025

Description

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:* 3.4.7 (including)