NA - CVE-2024-46610 - An access control issue in IceCMS v3.4.7 and...
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint...
Date: September 24, 2024 Revision Date Changes 1.0 September 24, 2024 Initial release The CVE-ID tracking this issue: CVE-2024-7142 CVSSv3.1 Base Score: 4.6 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)Common Weakness Enumeration: CWE-311: Missing...