Cross-Site Scripting Vulnerability in IceWarp Webclient by IceWarp
CVE-2010-5337

6.1MEDIUM

Key Information:

Vendor

Icewarp

Status
Vendor
CVE Published:
11 October 2019

What is CVE-2010-5337?

The IceWarp Webclient prior to version 10.2.1 is susceptible to a non-persistent Cross-Site Scripting (XSS) attack due to inadequate input validation in HTTP POST requests, specifically through the '_dlg[captcha][controller]' parameter. This vulnerability occurs in versions 10.1.3 and 10.2.0, allowing attackers to execute malicious scripts in the context of an unsuspecting user's session, potentially leading to information theft or account takeover.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.