Cross Site Scripting Vulnerability in IceWarp WebClient
CVE-2023-43319
6.1MEDIUM
What is CVE-2023-43319?
A Cross Site Scripting (XSS) vulnerability exists in the Sign-In page of IceWarp WebClient version 10.3.5. Attackers can exploit this flaw by injecting a crafted payload into the username parameter, enabling the execution of arbitrary web scripts or HTML. This can lead to unauthorized actions on behalf of users and compromise the integrity of sensitive data.
