QID 730908
Date Published: 2023-09-20
QID 730908: IceWarp Server Cross-Site Scripting (XSS) Vulnerability
IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
Affected Versions:
IceWarp 11.4.6.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable IceWarp server by sending a crafted XSS payload and checking for JS execution in the response.
Successful exploitation of the vulnerability may allow remote attackers to execute arbitrary JavaScript, steal cookies and perform other malicious activities.
Solution
Customers are advised to upgrade to the latest version of IceWarp Server. For more information please refer to IceWarp
Vendor References
CVEs related to QID 730908
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|