CVE-2017-7855: XSS
Published Aug 31, 2017
·Updated
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
Affected Software
1 affected component
IceWarp Server=11.3.1.5
Event History
Aug 31, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7855?
CVE-2017-7855 is rated as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2017-7855?
To mitigate CVE-2017-7855, upgrade to a version of IceWarp Server that is not vulnerable, specifically a version higher than 11.3.1.5.
3
What type of vulnerability is CVE-2017-7855?
CVE-2017-7855 is classified as a cross-site scripting (XSS) vulnerability.
4
What component is affected by CVE-2017-7855?
CVE-2017-7855 affects the webmail component of IceWarp Server version 11.3.1.5.
5
Who is affected by CVE-2017-7855?
Any users or organizations utilizing IceWarp Server version 11.3.1.5 are vulnerable to CVE-2017-7855.