First published: Fri Oct 11 2019(Updated: )
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Webclient | >=10.0<10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-5337 is medium with a score of 6.1.
CVE-2010-5337 affects IceWarp Webclient versions between 10.0 and 10.2.1.
The cause of CVE-2010-5337 is a cross-site scripting (XSS) vulnerability in IceWarp Webclient before version 10.2.1.
To fix CVE-2010-5337, it is recommended to upgrade to IceWarp Webclient version 10.2.1 or later.
You can find more information about CVE-2010-5337 at the following references: [link1] [link2].