Open Redirect Vulnerability in IceWarp MailServer by IceWarp
CVE-2021-36580
6.1MEDIUM
What is CVE-2021-36580?
An Open Redirect vulnerability in IceWarp MailServer allows attackers to manipulate the 'referer' parameter, potentially leading users to malicious sites. This flaw poses a security risk as it can be exploited to perform phishing attacks or to direct users unwittingly to untrusted locations. Organizations using IceWarp Server Deep Castle 2 Update 1 should take immediate steps to mitigate this vulnerability.
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
