First published: Tue Aug 23 2022(Updated: )
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp WebClient DC2 | =13.0.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35115 is a SQL injection vulnerability found in IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9).
CVE-2022-35115 has a severity rating of 9.8 (critical).
The software version affected by CVE-2022-35115 is IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9).
To fix CVE-2022-35115, update to DC2 Update 2 Build 10 (13.0.2.10) or later.
You can find more information about CVE-2022-35115 in the IceWarp Community Post and the CVE-2022-35115.txt file.