Record summary

CVE-2019-12593 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBIceWarp 10.4.4 - Local File InclusionExploitDB exploitby JameelNabboNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHIceWarp Mail Server <=10.4.4 - Local File InclusionCVSS 7.5

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

Impact

An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.

Remediation

Upgrade IceWarp Mail Server to a version higher than 10.4.4 or apply the vendor-provided patch to fix the LFI vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2019packetstormlfiicewarpvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:icewarp:mail_server:*:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp server administration"
Shodan: http.title:"icewarp"
Shodan: cpe:"cpe:2.3:a:icewarp:mail_server"
FOFA: title="icewarp server administration"
FOFA: title="icewarp"
Google: Powered By IceWarp 10.4.4
Google: intitle:"icewarp"
Google: powered by icewarp 10.4.4
Google: intitle:"icewarp server administration"

Source: ProjectDiscovery

References

3