Vulnerabilities > Macwk

DATE CVE VULNERABILITY TITLE RISK
2023-10-27 CVE-2023-42188 Cross-Site Request Forgery (CSRF) vulnerability in Macwk Icecms 2.0.1
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
network
low complexity
macwk CWE-352
6.5
2023-09-01 CVE-2023-36100 Unspecified vulnerability in Macwk Icecms 2.0.1
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.
network
low complexity
macwk
critical
9.8