PT-2017-12721 · Icewarp · Icewarp Mail Server
Published
2017-08-23
·
Updated
2017-08-29
·
CVE-2017-12844
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IceWarp Mail Server version 10.4.4
Description
A cross-site scripting (XSS) issue exists in the admin panel, allowing remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted
user name. This could potentially lead to unauthorized actions on the affected system.Recommendations
For IceWarp Mail Server version 10.4.4, consider restricting access to the admin panel until a fix is available, and avoid using crafted user names to prevent potential exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icewarp Mail Server