CVE-2024-46607
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 284
Summary
CVE-2024-46607 is a new vulnerability affecting IceCMS version 3.4.7 and older. This issue stems from incorrect access control in the UserController.java file's loginAdmin method. Attackers can exploit this flaw by entering any arbitrary values for both the username and password during the authentication process. Successful exploitation grants unauthorized access to the affected system. This vulnerability poses a significant risk and requires immediate attention from IceCMS users to patch or upgrade their installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- iceCMS