High severity7.5NVD Advisory· Published Sep 25, 2024· Updated Jun 17, 2026
CVE-2024-46610
CVE-2024-46610
Description
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- IceCMS/IceCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/Lunax0/LogLunax/blob/main/icecms/CVE-2024-46610.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.