CVE-2023-40779
IceWarp Mail Server Deep Castle 2 v.13.0.1.2 - Open Redirect
Record summary
CVE-2023-40779 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMIceWarp Mail Server Deep Castle 2 v.13.0.1.2 - Open RedirectCVSS 6.1
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
Impact
Attackers can craft malicious redirect URLs to phish IceWarp Mail Server users, potentially stealing email credentials by redirecting victims to attacker-controlled domains that mimic the legitimate login page.
Remediation
Update IceWarp Mail Server Deep Castle 2 to a version newer than 13.0.1.2 that validates redirect URLs and prevents open redirect attacks.
Source: ProjectDiscovery