First published: Sat Jun 30 2018(Updated: )
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Mail Server | =12.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7475 is a Cross-site scripting (XSS) vulnerability in IceWarp Mail Server 12.0.3.
CVE-2018-7475 allows remote attackers to inject arbitrary web script or HTML using the webdav/ticket/ URIs.
CVE-2018-7475 has a severity keyword of 'medium' and a severity value of 6.1.
To fix CVE-2018-7475, it is recommended to update IceWarp Mail Server to version 12.0.4 or later.
You can find more information about CVE-2018-7475 at the following references: [Link 1](https://0xd0ff9.wordpress.com/2018/06/21/cve-2018-7475/), [Link 2](https://www.youtube.com/watch?v=8_3Q80JrMm4).