Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Icecms | Thecosy | * | 3.4.7 (including) |