Vulnerability CVE-2024-46607


Published: 2024-09-25

Description:
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.

 References:
http://icecms.com
https://github.com/Thecosy/iceCMS?tab=readme-ov-file
https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md

Copyright 2026, cxsecurity.com

 

Back to Top