First published: Fri Sep 01 2023(Updated: )
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icecms | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in IceCMS version 2.0.1 is CVE-2023-36100.
CVE-2023-36100 has a severity rating of critical (9.8).
The affected software for CVE-2023-36100 is IceCMS version 2.0.1.
An attacker can escalate privileges and gain sensitive information through the UserID parameter in 'api/User/ChangeUser' using CVE-2023-36100.
Yes, you can find more information about CVE-2023-36100 at the following reference: [https://github.com/Thecosy/IceCMS/issues/15](https://github.com/Thecosy/IceCMS/issues/15).