QID 730908

Date Published: 2023-09-20

QID 730908: IceWarp Server Cross-Site Scripting (XSS) Vulnerability

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

Affected Versions:
IceWarp 11.4.6.0

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable IceWarp server by sending a crafted XSS payload and checking for JS execution in the response.

Successful exploitation of the vulnerability may allow remote attackers to execute arbitrary JavaScript, steal cookies and perform other malicious activities.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to the latest version of IceWarp Server. For more information please refer to IceWarp

    Vendor References

    CVEs related to QID 730908

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo www.icewarp.com/