First published: Tue Sep 05 2023(Updated: )
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Webclient | =10.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39598 is a Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 that allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
CVE-2023-39598 affects IceWarp WebClient v.10.2.1 by enabling a remote attacker to execute arbitrary code through a specially crafted payload to the mid parameter.
The severity of CVE-2023-39598 is medium with a CVSS score of 6.1.
To fix CVE-2023-39598 in IceWarp WebClient v.10.2.1, it is recommended to update to a patched version provided by IceWarp Corporation.
Yes, you can find more information about CVE-2023-39598 at the following link: [Reference](https://medium.com/@muthumohanprasath.r/reflected-cross-site-scripting-on-icewarp-webclient-product-cve-2023-39598-9598b92da49c)