Cross-Site Scripting Vulnerability in IceWarp Webclient by IceWarp
CVE-2010-5338
6.1MEDIUM
What is CVE-2010-5338?
The IceWarp Webclient is susceptible to a Cross-Site Scripting (XSS) flaw that can be exploited through an HTTP POST request, particularly affecting the webmail/basic/ endpoint. This vulnerability arises from the non-persistent nature of the _dlg[captcha][action] parameter, exposing users to potential data theft or session hijacking. Users of versions 10.1.3 and 10.2.0 are particularly at risk, prior to the release of version 10.2.1 which addresses this flaw.
