CVE-2019-12593
icewarp mail_server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-12593 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
mail_serverBrowse icewarp / mail_server | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBIceWarp 10.4.4 - Local File InclusionExploitDB exploitby JameelNabboNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHIceWarp Mail Server <=10.4.4 - Local File InclusionCVSS 7.5
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
Impact
An attacker can read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.
Remediation
Upgrade IceWarp Mail Server to a version higher than 10.4.4 or apply the vendor-provided patch to fix the LFI vulnerability.
Source: ProjectDiscovery