{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-6756","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-12-13T07:39:44.413Z","datePublished":"2023-12-13T13:31:03.944Z","dateUpdated":"2024-08-02T08:42:07.179Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-12-13T13:31:03.944Z"},"title":"Thecosy IceCMS Captcha login excessive authentication","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-307","lang":"en","description":"CWE-307 Improper Restriction of Excessive Authentication Attempts"}]}],"affected":[{"vendor":"Thecosy","product":"IceCMS","versions":[{"version":"2.0.1","status":"affected"}],"modules":["Captcha Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247884."},{"lang":"de","value":"Es wurde eine problematische Schwachstelle in Thecosy IceCMS 2.0.1 ausgemacht. Betroffen hiervon ist ein unbekannter Ablauf der Datei /login der Komponente Captcha Handler. Durch Beeinflussen mit unbekannten Daten kann eine improper restriction of excessive authentication attempts-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N"}}],"timeline":[{"time":"2023-12-13T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-12-13T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-12-13T08:45:15.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"YuJiu (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.247884","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.247884","tags":["signature","permissions-required"]},{"url":"http://124.71.147.32:8082/IceCMS2.html","tags":["exploit"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T08:42:07.179Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.247884","tags":["vdb-entry","x_transferred"]},{"url":"https://vuldb.com/?ctiid.247884","tags":["signature","permissions-required","x_transferred"]},{"url":"http://124.71.147.32:8082/IceCMS2.html","tags":["exploit","x_transferred"]}]}]}}