Record summary

CVE-2023-39700 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMIceWarp Mail Server v10.4.5 - Cross-Site ScriptingCVSS 6.1

IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.

Impact

Unauthenticated attackers can inject malicious JavaScript through the color parameter in the webmail interface to steal email user session cookies and access sensitive email communications.

Remediation

Update IceWarp Mail Server to a version newer than 10.4.5 that properly sanitizes the color parameter and encodes output in the webmail interface.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2023icewarpxssunauthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:icewarp:mail_server:10.4.5:*:*:*:*:*:*:*
Shodan: http.title:"IceWarp Server Administration"
Shodan: http.title:"icewarp server administration"
Shodan: http.title:"icewarp"
Shodan: cpe:"cpe:2.3:a:icewarp:mail_server"
FOFA: title="icewarp server administration"
FOFA: title="icewarp"
Google: intitle:"icewarp server administration"
Google: intitle:"icewarp"
Google: powered by icewarp 10.4.4

Source: ProjectDiscovery

References

5