PoC Index

CVE-2024-46607

HIGH 7.6EPSS 0.5%

Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.

CVSS v3.1
7.6 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
EPSS
0.49% chance of exploitation in the next 30 days, 40th percentile
Published
2024-09-24
Updated
2026-07-05

Proof-of-concept exploits (1)

References

Related