CVE-2018-25269: ICEWARP 11.0.0.0 Cross-Site Scripting via Email HTML Injection
ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25269?
CVE-2018-25269 is scored as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2018-25269?
To fix CVE-2018-25269, upgrade IceWarp to a version that addresses the cross-site scripting vulnerability.
What software is affected by CVE-2018-25269?
CVE-2018-25269 affects IceWarp version 11.0.0.0.
What type of vulnerability is CVE-2018-25269?
CVE-2018-25269 is categorized as a cross-site scripting (XSS) vulnerability.
What could attackers do with CVE-2018-25269?
Attackers can exploit CVE-2018-25269 to inject malicious HTML into emails, potentially compromising user data or session information.