
Thecosy/IceCMS
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 7.6 HIGH | — | ||
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file. | |||
| 7.5 HIGH | — | ||
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords | |||
| 7.5 HIGH | — | ||
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java | |||
| 9.8 CRITICAL | — | ||
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. | |||
| 6.5 MEDIUM | — | ||
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | |||
| 9.8 CRITICAL | — | ||
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser. | |||
| 5.4 MEDIUM | — | ||
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS). | |||
| 7.5 HIGH | — | ||
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information. | |||