Record summary

CVE-2023-39598 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 30, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp Email Client - Cross Site ScriptingCVSS 6.1

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

WeaknessesCWE-79
AuthorsImjust0
Template tagscve2023cvexssicewarpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:webclient:10.2.1:*:*:*:*:*:*:*
Shodan: title:"icewarp"
Shodan: http.title:"icewarp"
FOFA: title="icewarp"
Google: intitle:"icewarp"

Source: ProjectDiscovery

References

3