CVE-2023-39598: XSS
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39598?
CVE-2023-39598 is a Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 that allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
How does CVE-2023-39598 affect IceWarp WebClient v.10.2.1?
CVE-2023-39598 affects IceWarp WebClient v.10.2.1 by enabling a remote attacker to execute arbitrary code through a specially crafted payload to the mid parameter.
What is the severity of CVE-2023-39598?
The severity of CVE-2023-39598 is medium with a CVSS score of 6.1.
How can I fix CVE-2023-39598 in IceWarp WebClient v.10.2.1?
To fix CVE-2023-39598 in IceWarp WebClient v.10.2.1, it is recommended to update to a patched version provided by IceWarp Corporation.
Is there any reference for CVE-2023-39598?
Yes, you can find more information about CVE-2023-39598 at the following link: [Reference](https://medium.com/@muthumohanprasath.r/reflected-cross-site-scripting-on-icewarp-webclient-product-cve-2023-39598-9598b92da49c)