Record summary

CVE-2017-7855 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp WebMail 11.3.1.5 - Cross-Site ScriptingCVSS 6.1

IceWarp WebMail 11.3.1.5 is vulnerable to cross-site scripting via the language parameter.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Apply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2017xssicewarpvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:server:11.3.1.5:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"gotify"
FOFA: title="gotify"
Google: intitle:"gotify"

Source: ProjectDiscovery

References

2