CVE-2025-40630: Open redirection vulnerability in IceWarp Mail Server
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUSDOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40630?
CVE-2025-40630 is considered a high severity vulnerability due to its potential for exploitation through open redirection.
How do I fix CVE-2025-40630?
To fix CVE-2025-40630, update your IceWarp Mail Server to the latest version that has patched this vulnerability.
What versions of IceWarp Mail Server are affected by CVE-2025-40630?
CVE-2025-40630 affects IceWarp Mail Server version 11.4.0 and possibly earlier versions.
What type of attacks can CVE-2025-40630 facilitate?
CVE-2025-40630 can facilitate attacks such as phishing by redirecting users to malicious domains.
Is user data at risk due to CVE-2025-40630?
While CVE-2025-40630 does not directly compromise user data, it can lead to phishing and other attacks that endanger user credentials.