A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247888.
Weaknesses in this category are related to the design and architecture of session management. Frequently these deal with the information or status about each user and their access rights for the duration of multiple requests. The weaknesses in this category could lead to a degradation of the quality of session management if they are not addressed when designing or implementing a secure architecture.
Link | Tags |
---|---|
https://vuldb.com/?id.247888 | third party advisory vdb entry |
https://vuldb.com/?ctiid.247888 | signature third party advisory permissions required |
http://39.106.130.187/yue/yue.html | third party advisory exploit |