CVE-2024-46609

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
Configurations

No configuration.

History

27 Sep 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.5

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Un problema de control de acceso en la función CheckVip en UserController.java de IceCMS v3.4.7 y anteriores permite a atacantes no autenticados acceder y devolver toda la información del usuario, incluidas las contraseñas.

25 Sep 2024, 01:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-284

25 Sep 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-25 01:15

Updated : 2024-09-27 16:35


NVD link : CVE-2024-46609

Mitre link : CVE-2024-46609

CVE.ORG link : CVE-2024-46609


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control