Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-46610

Description

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

POC

Reference

- https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46610.md

Github

- https://github.com/Lunax0/CVE_List

- https://github.com/fkie-cad/nvd-json-data-feeds