CVE-2023-37728
IceWarp Webmail Server v10.2.1 - Cross Site Scripting
Record summary
CVE-2023-37728 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp Webmail Server v10.2.1 - Cross Site ScriptingCVSS 6.1
Icewarp Icearp v10.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
Impact
Unauthenticated attackers can inject malicious JavaScript through the color parameter to steal webmail user session cookies and access email communications.
Remediation
Update IceWarp to a version newer than 10.2.1 that properly sanitizes the color parameter and encodes output in the webmail interface.
Source: ProjectDiscovery