We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-40630

Open redirection vulnerability in IceWarp Mail Server



Description

Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.

Reserved 2025-04-16 | Published 2025-05-16 | Updated 2025-05-16 | Assigner INCIBE


MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Problem types

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

Product status

Default status
unaffected

11.4.0
affected

Credits

Julen Garrido Estévez finder

References

www.incibe.es/...ultiple-vulnerabilities-icewarp-mail-server

cve.org (CVE-2025-40630)

nvd.nist.gov (CVE-2025-40630)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-40630

Support options

Helpdesk Chat, Email, Knowledgebase