Record summary

CVE-2020-8512 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBIceWarp WebMail 11.4.4.1 - Reflective Cross-Site ScriptingExploitDB exploitby Lutfu Mert CeylanNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp WebMail Server <=11.4.4.1 - Cross-Site ScriptingCVSS 6.1

IceWarp Webmail Server through 11.4.4.1 contains a cross-site scripting vulnerability in the /webmail/ color parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities.

Remediation

Upgrade to a patched version of IceWarp WebMail Server (>=11.4.4.2) or apply the vendor-provided patch to mitigate the vulnerability.

WeaknessesCWE-79
Authorspdteam, dwisiswant0
Template tagscvecve2020edbpacketstormxssicewarpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:icewarp_server:*:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp"
FOFA: title="icewarp"
Google: intitle:"icewarp"

Source: ProjectDiscovery

References

4