CVE-2024-46610: Thecosy Icecms
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
Affected products
- Thecosy Icecms: up to and including 3.4.7
Published 2024-09-25. Last modified 2026-06-17.