Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IceCMS 安全漏洞
Vulnerability Description
IceCMS是NgShow个人开发者的一个基于 Spring Boot + Vue 前后端分离的内容管理系统。 IceCMS v3.4.7及之前版本存在安全漏洞,该漏洞源于存在访问控制问题,允许攻击者通过发送精心设计的POST请求任意修改包括用户名和密码的用户信息。
CVSS Information
N/A
Vulnerability Type
N/A