macwk records
2 published records for vendor macwk.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-36100No exploit | An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parametermacwk · icecms · CWE-269 | Critical9.8 | — | 0.7% | Sep 1, 2023 |
26Monitor | CVE-2023-42188No exploit | IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).macwk · icecms · CWE-352 | Medium6.5 | — | 0.2% | Oct 26, 2023 |
- CVE-2023-3610039Monitor
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter
CriticalCVSS 9.8No exploitEPSS 1%macwk · icecmsSep 1, 2023
- CVE-2023-4218826Monitor
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
MediumCVSS 6.5No exploitEPSS 0%macwk · icecmsOct 26, 2023