CVE-2020-27982: XSS
Published Nov 2, 2020
·Updated
IceWarp 11.4.5.0 allows XSS via the language parameter.
Affected Software
1 affected component
IceWarp Mail Server=11.4.5
Event History
Nov 2, 2020
CVE Published
09:15 PM
Nov 9, 2020
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this IceWarp vulnerability?
The vulnerability ID for this IceWarp vulnerability is CVE-2020-27982.
2
What is the severity of CVE-2020-27982?
The severity of CVE-2020-27982 is medium with a CVSS score of 6.1.
3
How does IceWarp 11.4.5.0 allow XSS?
IceWarp 11.4.5.0 allows XSS via the language parameter.
4
Which software version is affected by CVE-2020-27982?
Version 11.4.5 of IceWarp Mail Server is affected by CVE-2020-27982.
5
How can I fix the XSS vulnerability in IceWarp 11.4.5.0?
To fix the XSS vulnerability in IceWarp 11.4.5.0, update to a version that has a patch or security fix available.