Skip to content

Instantly share code, notes, and snippets.

View Sholway's full-sized avatar
💭
SecTide

Jawsho Sholway

💭
SecTide
View GitHub Profile
@Sholway
Sholway / CVE-2023-40833
Last active October 13, 2023 01:11
CVE-2023-40833
[CVE ID]
CVE-2023-40833
[PRODUCT]
icecms
[VERSION]
v1.0.0
[Vulnerability TYPE]
Insecure Permissions
[Root Cause]
The icecms allows anyone to browser getSetting api,like my local test environment http://localhost:8181/WebSitting/getSetting,