CVE-2021-36580
IceWarp Mail Server - Open Redirect
Record summary
CVE-2021-36580 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp Mail Server - Open RedirectCVSS 6.1
IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or other unintended redirects.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
Remediation
Apply the latest security patches or updates provided by IceWarp to fix the open redirect vulnerability.
Source: ProjectDiscovery