CVE-2023-39700
IceWarp Mail Server v10.4.5 - Cross-Site Scripting
Record summary
CVE-2023-39700 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp Mail Server v10.4.5 - Cross-Site ScriptingCVSS 6.1
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Impact
Unauthenticated attackers can inject malicious JavaScript through the color parameter in the webmail interface to steal email user session cookies and access sensitive email communications.
Remediation
Update IceWarp Mail Server to a version newer than 10.4.5 that properly sanitizes the color parameter and encodes output in the webmail interface.
Source: ProjectDiscovery