Open Redirect Vulnerability in IceWarp MailServer by IceWarp
CVE-2021-36580

6.1MEDIUM

Key Information:

Vendor

Icewarp

Vendor
CVE Published:
27 July 2023

What is CVE-2021-36580?

An Open Redirect vulnerability in IceWarp MailServer allows attackers to manipulate the 'referer' parameter, potentially leading users to malicious sites. This flaw poses a security risk as it can be exploited to perform phishing attacks or to direct users unwittingly to untrusted locations. Organizations using IceWarp Server Deep Castle 2 Update 1 should take immediate steps to mitigate this vulnerability.

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.