CRLF Injection Vulnerability in IceWarp eMail Server and WebMail Server
CVE-2009-1469
What is CVE-2009-1469?
The CRLF injection vulnerability in IceWarp eMail Server and WebMail Server allows remote attackers to manipulate the 'Forgot Password' functionality. This weakness enables attackers to craft deceptive email messages that can trick users into inadvertently disclosing their credentials. The issue arises from the inclusion of CRLF sequences before the Reply-To header in the XML document's subject element. When the server generates an email containing valid user credentials, users may be misled into responding with sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved
