Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-40630 1 Icewarp 1 Mail Server 2025-10-09 6.1 Medium
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.
CVE-2025-40631 1 Icewarp 1 Mail Server 2025-10-09 6.1 Medium
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
CVE-2025-40632 1 Icewarp 1 Mail Server 2025-10-09 6.1 Medium
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.