Cyber Resilience

CVE-2023-6762

Thecosy Icecms 2.0.1

Public PoC
Published
13 December 2023
Modified
21 November 2024
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Score 0.0069 50th percentile
Risk Priority 45 floored blend · peak EPSS

Summary

CVE-2023-6762 is a medium-severity an unspecified weakness vulnerability in Thecosy Icecms. Its CVSS base score is 5.4 (Medium).

Operationally, ranked at the 50th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It is possible to launch the attack…

more

remotely. The exploit has been disclosed to the public and may be used. VDB-247890 is the identifier assigned to this vulnerability.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-46610Same product: Thecosy Icecms
CVE-2023-33355Same product: Thecosy Icecms
CVE-2025-22983Same product: Thecosy Icecms
CVE-2023-6756Same product: Thecosy Icecms
CVE-2023-6757Same product: Thecosy Icecms
CVE-2024-46609Same product: Thecosy Icecms
CVE-2023-6759Same product: Thecosy Icecms
CVE-2024-48202Same product: Thecosy Icecms
CVE-2023-40833Same product: Thecosy Icecms
CVE-2023-6761Same product: Thecosy Icecms

Affected Assets

thecosy
icecms
2.0.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References