Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
                
            References
                    | Link | Resource | 
|---|---|
| http://icecms.com | Product | 
| https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md | Exploit Third Party Advisory | 
| https://github.com/Thecosy/iceCMS?tab=readme-ov-file | Product | 
Configurations
                    History
                    28 Apr 2025, 17:09
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:thecosy:icecms:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| References | () http://icecms.com - Product | |
| References | () https://github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46607.md - Exploit, Third Party Advisory | |
| References | () https://github.com/Thecosy/iceCMS?tab=readme-ov-file - Product | |
| First Time | Thecosy icecms Thecosy | 
26 Sep 2024, 13:32
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
25 Sep 2024, 01:36
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-284 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.6 | 
25 Sep 2024, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-09-25 01:15
Updated : 2025-04-28 17:09
NVD link : CVE-2024-46607
Mitre link : CVE-2024-46607
CVE.ORG link : CVE-2024-46607
JSON object : View
Products Affected
                thecosy
- icecms
CWE
                