CVE-2018-7475: XSS
Published Jun 30, 2018
·Updated
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
Affected Software
1 affected component
IceWarp Mail Server=12.0.3
Event History
Jun 30, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-7475?
CVE-2018-7475 is a Cross-site scripting (XSS) vulnerability in IceWarp Mail Server 12.0.3.
2
How does CVE-2018-7475 affect IceWarp Mail Server?
CVE-2018-7475 allows remote attackers to inject arbitrary web script or HTML using the webdav/ticket/ URIs.
3
What is the severity of CVE-2018-7475?
CVE-2018-7475 has a severity keyword of 'medium' and a severity value of 6.1.
4
How can I fix CVE-2018-7475?
To fix CVE-2018-7475, it is recommended to update IceWarp Mail Server to version 12.0.4 or later.
5
Where can I find more information about CVE-2018-7475?
You can find more information about CVE-2018-7475 at the following references: [Link 1](https://0xd0ff9.wordpress.com/2018/06/21/cve-2018-7475/), [Link 2](https://www.youtube.com/watch?v=8_3Q80JrMm4).