25 lines
818 B
JSON
Raw Normal View History

{
"id": "CVE-2024-46610",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-09-25T01:15:44.497",
"lastModified": "2024-09-25T01:15:44.497",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java"
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46610.md",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/Thecosy/iceCMS?tab=readme-ov-file",
"source": "cve@mitre.org"
}
]
}