First published: Wed Dec 13 2023(Updated: )
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247884.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6756 is classified as problematic, indicating it poses a risk to affected systems.
To fix CVE-2023-6756, update to the latest version of IceCMS that addresses the vulnerability.
CVE-2023-6756 specifically affects IceCMS version 2.0.1.
CVE-2023-6756 involves improper restriction of excessive authentication attempts within the Captcha Handler component.
The impact of CVE-2023-6756 allows attackers to potentially launch brute-force attacks due to the weak restriction on authentication attempts.