Cross-Site Scripting Vulnerability in IceWarp Webclient by IceWarp
CVE-2010-5337
6.1MEDIUM
What is CVE-2010-5337?
The IceWarp Webclient prior to version 10.2.1 is susceptible to a non-persistent Cross-Site Scripting (XSS) attack due to inadequate input validation in HTTP POST requests, specifically through the '_dlg[captcha][controller]' parameter. This vulnerability occurs in versions 10.1.3 and 10.2.0, allowing attackers to execute malicious scripts in the context of an unsuspecting user's session, potentially leading to information theft or account takeover.
