CVE-2024-46607

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 284

Summary

CVE-2024-46607 is a new vulnerability affecting IceCMS version 3.4.7 and older. This issue stems from incorrect access control in the UserController.java file's loginAdmin method. Attackers can exploit this flaw by entering any arbitrary values for both the username and password during the authentication process. Successful exploitation grants unauthorized access to the affected system. This vulnerability poses a significant risk and requires immediate attention from IceCMS users to patch or upgrade their installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share