CVE-2010-5336: XSS
Published Oct 11, 2019
·Updated
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.
Affected Software
1 affected component
IceWarp Webclient<10.2.1
Event History
Oct 11, 2019
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-5336?
The severity of CVE-2010-5336 is medium with a severity value of 6.1.
2
How does CVE-2010-5336 affect IceWarp Webclient?
CVE-2010-5336 affects IceWarp Webclient versions up to and excluding 10.2.1.
3
What is the CWE ID for CVE-2010-5336?
The CWE ID for CVE-2010-5336 is 79.
4
How can I fix CVE-2010-5336?
To fix CVE-2010-5336, update IceWarp Webclient to version 10.2.1 or higher.
5
Where can I find more information about CVE-2010-5336?
You can find more information about CVE-2010-5336 at the following references: [VulDB](https://vuldb.com/?id.142993) and [GoSecurity Advisory](https://www.gosecurity.ch/component/content/article/12-services/gosecuritynews/fachartikel/169-gosecurity-advisory-2010120602).