CVE-2023-41013: XSS
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41013?
CVE-2023-41013 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML in the Webmail Calendar in IceWarp 10.3.1.
How severe is CVE-2023-41013?
CVE-2023-41013 has a severity rating of 6.1, which is considered medium.
What software is affected by CVE-2023-41013?
IceWarp 10.3.1 is the affected software.
How can remote attackers exploit CVE-2023-41013?
Remote attackers can exploit CVE-2023-41013 by injecting arbitrary web script or HTML via the "p4" field in the Webmail Calendar.
Are there any references for CVE-2023-41013?
Yes, you can find references for CVE-2023-41013 at the following links: [http://icewrap.com](http://icewrap.com) and [https://medium.com/@katikitala.sushmitha078/cve-2023-41013-789841dcad91](https://medium.com/@katikitala.sushmitha078/cve-2023-41013-789841dcad91)