Record summary

CVE-2023-37728 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp Webmail Server v10.2.1 - Cross Site ScriptingCVSS 6.1

Icewarp Icearp v10.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

Impact

Unauthenticated attackers can inject malicious JavaScript through the color parameter to steal webmail user session cookies and access email communications.

Remediation

Update IceWarp to a version newer than 10.2.1 that properly sanitizes the color parameter and encodes output in the webmail interface.

WeaknessesCWE-79
Authorstechnicaljunkie, r3Y3r53
Template tagscvecve2023icearpicewarpxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:icewarp:10.2.1:*:*:*:*:*:*:*
Shodan: http.favicon.hash:2144485375
Shodan: http.title:"icewarp"
FOFA: title="icewarp"
FOFA: icon_hash=2144485375
Google: intitle:"icewarp"

Source: ProjectDiscovery

References

6