CVE-2019-19266: XSS
Published Jan 6, 2020
·Updated
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
Affected Software
1 affected component
IceWarp Mail Server<12.2.1.1
Event History
Jan 6, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-19266?
CVE-2019-19266 is a vulnerability in IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 that allows XSS in notes for objects.
2
How severe is CVE-2019-19266?
CVE-2019-19266 has a severity rating of medium.
3
How does CVE-2019-19266 affect IceWarp WebMail Server?
CVE-2019-19266 affects IceWarp WebMail Server versions 12.2.0 and 12.1.x before 12.2.1.1.
4
What is the Common Weakness Enumeration (CWE) of CVE-2019-19266?
The CWE of CVE-2019-19266 is CWE-79, which is a vulnerability related to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2019-19266 vulnerability?
To fix CVE-2019-19266, users should update their IceWarp WebMail Server to version 12.2.1.1 or higher.