Описание
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Ссылки
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00031
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-644
Связанные уязвимости
CVSS3: 6.1
github
9 месяцев назад
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
EPSS
Процентиль: 8%
0.00031
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-644