CVE-2018-25269
MEDIUMICEWARP 11.0.0.0 Cross-Site Scripting via Email HTML Injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25269. PoCs published by Usman Saeed.
AI-analyzed exploit summary The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in IceWarp WebMail client versions 11.0.0.0 and 10.3.4. It uses embedded SVG and object elements with base64-encoded payloads to trigger arbitrary JavaScript execution in the context of the victim's browser.
Description
ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.
Exploits (1)
The exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in IceWarp WebMail client versions 11.0.0.0 and 10.3.4. It uses embedded SVG and object elements with base64-encoded payloads to trigger arbitrary JavaScript execution in the context of the victim's browser.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N