First published: Fri Oct 11 2019(Updated: )
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Webclient | >=10.0<10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2010-5339.
The severity of CVE-2010-5339 is medium with a severity value of 6.1.
The affected software is IceWarp Webclient version 10.0 to 10.2.1.
The vulnerability occurs via an XSS (Cross-Site Scripting) attack through an HTTP POST request to the webmail/basic/ endpoint with the parameter _dlg[captcha][uid].
To fix CVE-2010-5339, it is recommended to upgrade to IceWarp Webclient version 10.2.1 or higher.