Loading vulnerability details…
CVSS v3.1
7.6
EPSS
0.49%
Published
Sep 24, 2024
Modified
Apr 28, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:LWeaknesses (CWE)
Affected Products (1)
References (3)