Security Advisory

CVE-2024-46610

7.5
HIGH

Vulnerability Description

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
Published Date September 25, 2024
Official Source NIST NVD Advisory