Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-25269

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:icewarp:icewarp:11.0.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.0023
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
3 месяца назад

ICEWARP 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.

EPSS

Процентиль: 14%
0.0023
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79