Cross-Site Scripting Vulnerability in IceWarp WebMail Server
CVE-2019-19265

6.1MEDIUM

Key Information:

Vendor

Icewarp

Vendor
CVE Published:
6 January 2020

What is CVE-2019-19265?

A Cross-Site Scripting (XSS) vulnerability exists in IceWarp WebMail Server versions 12.2.0 and 12.1.x prior to 12.2.1.1, allowing attackers to inject malicious scripts into the notes feature for contacts. This issue could potentially be exploited to execute arbitrary scripts in the context of the user's browser, leading to unauthorized access to sensitive information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.