CVE-2023-39699

CRITICAL

IceWarp Mail Server 10.4.5 - Local File Inclusion via Calendar Minimizer

Title source: llm
STIX 2.1

Description

IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.

Scores

CVSS v3 9.8
EPSS 0.0116
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
icewarp/mail_server 10.4.5
Published Aug 25, 2023
Tracked Since Feb 18, 2026