First published: Thu Aug 24 2023(Updated: )
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IceWarp Mail Server | =10.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39700 is a reflected cross-site scripting (XSS) vulnerability found in IceWarp Mail Server v10.4.5.
CVE-2023-39700 has a severity rating of 6.1 (medium).
CVE-2023-39700 affects IceWarp Mail Server v10.4.5 through a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Cross-site scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To prevent cross-site scripting (XSS) attacks, sanitize user input, use proper output encoding, and implement content security policies (CSP).