First published: Thu Oct 12 2023(Updated: )
An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icecms | =1.0.0 | |
iCMS | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-40833 is critical.
Thecosy IceCMS v.1.0.0 is affected by CVE-2023-40833.
A remote attacker can exploit CVE-2023-40833 by using the Id and key parameters in the getCosSetting function of Thecosy IceCMS v.1.0.0 to gain privileges.
At the moment, there is no known fix for CVE-2023-40833. It is recommended to mitigate the risk by implementing appropriate security measures, such as restricting access to the affected software.
More information about CVE-2023-40833 can be found at the following link: [https://gist.github.com/Sholway/93f05987dbf35c15c26de32b1e5590ec](https://gist.github.com/Sholway/93f05987dbf35c15c26de32b1e5590ec).