Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
- https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md
- https://github.com/Lunax0/CVE_List