nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-7855 CVE-2017-7855
MEDIUMNuclei
IceWarp WebMail 11.3.1.5 - Cross-Site Scripting
Record summary
CVE-2017-7855 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp WebMail 11.3.1.5 - Cross-Site ScriptingCVSS 6.1
IceWarp WebMail 11.3.1.5 is vulnerable to cross-site scripting via the language parameter.
Impact
Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail.
WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2017xssicewarpvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:server:11.3.1.5:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"gotify"
FOFA: title="gotify"
Google: intitle:"gotify"
https://technical.nttsecurity.com/post/102eegq/cookies-are-delicious https://nvd.nist.gov/vuln/detail/CVE-2017-7855
Source: ProjectDiscovery
References
2technical.nttsecurity.com
https://technical.nttsecurity.com/post/102eegq/cookies-are-delicious