Home
LOW: 2.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NDefault status
unaffected
11.4.0
affected
Description
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
11.4.0
Credits
Julen Garrido Estévez
References
www.incibe.es/...ultiple-vulnerabilities-icewarp-mail-server