CVE-2018-16324: XSS
Published Sep 1, 2018
·Updated
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
Affected Software
1 affected component
IceWarp Mail Server<=12.0.3.1
Event History
Sep 1, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the IceWarp Server XSS?
The vulnerability ID for the IceWarp Server XSS is CVE-2018-16324.
2
What is the severity of CVE-2018-16324?
The severity of CVE-2018-16324 is medium with a CVSS score of 6.1.
3
Which version of IceWarp Server is affected by CVE-2018-16324?
IceWarp Server version 12.0.3.1 and earlier is affected by CVE-2018-16324.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-16324?
The Common Weakness Enumeration (CWE) ID for CVE-2018-16324 is CWE-79.
5
How can I fix the XSS vulnerability in IceWarp Server?
To fix the XSS vulnerability in IceWarp Server, update to a version later than 12.0.3.1.