CVE-2023-36100: Macwk Icecms

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

Affected products

  • Macwk Icecms: version 2.0.1 only

Published 2023-09-01. Last modified 2026-06-17.