dl.icewarp.com
http://dl.icewarp.com/patchinfo/11.4.5.txt CVE-2020-27982
MEDIUMNuclei
icewarp mail_server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2020-27982 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
IceWarp 11.4.5.0 allows XSS via the language parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
mail_serverBrowse icewarp / mail_server | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp WebMail 11.4.5.0 - Cross-Site ScriptingCVSS 6.1
IceWarp WebMail 11.4.5.0 is vulnerable to cross-site scripting via the language parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail.
WeaknessesCWE-79
Authorsmadrobot
Template tagscvecve2020xssicewarppacketstormvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:mail_server:11.4.5:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp server administration"
Shodan: http.title:"icewarp"
Shodan: cpe:"cpe:2.3:a:icewarp:mail_server"
FOFA: title="icewarp server administration"
FOFA: title="icewarp"
Google: intitle:"icewarp server administration"
Google: intitle:"icewarp"
Google: powered by icewarp 10.4.4
https://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html https://cxsecurity.com/issue/WLB-2020100161 https://nvd.nist.gov/vuln/detail/CVE-2020-27982 http://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/159763/Icewarp-WebMail-11.4.5.0-Cross-Site-Scripting.html cxsecurity.com
https://cxsecurity.com/issue/WLB-2020100161 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-27982