Record summary

CVE-2021-36580 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp Mail Server - Open RedirectCVSS 6.1

IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or other unintended redirects.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.

Remediation

Apply the latest security patches or updates provided by IceWarp to fix the open redirect vulnerability.

WeaknessesCWE-601
AuthorsDhiyaneshDk
Template tagscve2021cveicewarpredirectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:icewarp_server:*:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp"
FOFA: title="icewarp"
Google: intitle:"icewarp"

Source: ProjectDiscovery

References

5