Required CVE Record Information
Description
A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247888.
CVSS 3 Total
Score | Severity | Version | Vector String |
---|---|---|---|
6.3 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.3 | MEDIUM | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.5 | — | 2.0 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Credits
- zero121 (VulDB User) analyst
References 3 Total
- https://vuldb.com/?id.247888 vdb-entry
- https://vuldb.com/?ctiid.247888 signaturepermissions-required
- http://39.106.130.187/yue/yue.html exploit
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://vuldb.com/?id.247888 vdb-entryx_transferred
- https://vuldb.com/?ctiid.247888 signaturepermissions-requiredx_transferred
- http://39.106.130.187/yue/yue.html exploitx_transferred