CVE-2020-8512
MEDIUMNuclei
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
Record summary
CVE-2020-8512 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBIceWarp WebMail 11.4.4.1 - Reflective Cross-Site ScriptingExploitDB exploitby Lutfu Mert CeylanNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp WebMail Server <=11.4.4.1 - Cross-Site ScriptingCVSS 6.1
IceWarp Webmail Server through 11.4.4.1 contains a cross-site scripting vulnerability in the /webmail/ color parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities.
Remediation
Upgrade to a patched version of IceWarp WebMail Server (>=11.4.4.2) or apply the vendor-provided patch to mitigate the vulnerability.
WeaknessesCWE-79
Authorspdteam, dwisiswant0
Template tagscvecve2020edbpacketstormxssicewarpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:icewarp_server:*:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp"
FOFA: title="icewarp"
Google: intitle:"icewarp"
https://www.exploit-db.com/exploits/47988 https://twitter.com/sagaryadav8742/status/1275170967527006208 https://cxsecurity.com/issue/WLB-2020010205 https://packetstormsecurity.com/files/156103/IceWarp-WebMail-11.4.4.1-Cross-Site-Scripting.html https://nvd.nist.gov/vuln/detail/CVE-2020-8512
Source: ProjectDiscovery
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/156103/IceWarp-WebMail-11.4.4.1-Cross-Site-Scripting.html cxsecurity.com
https://cxsecurity.com/issue/WLB-2020010205 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-8512 packetstormsecurity.com
https://packetstormsecurity.com/files/156103/IceWarp-WebMail-11.4.4.1-Cross-Site-Scripting.html