CVE-2024-46610: Thecosy Icecms

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

Affected products

  • Thecosy Icecms: up to and including 3.4.7

Published 2024-09-25. Last modified 2026-06-17.