ID EDB-ID-47988
CVSS 3.0 N/A
Cloudbric Score
Cloudbric Detection Yes
Vulnerability Type Link
Published Date 2020-02-03
Updated Date 2020-02-03
Vendor N/A
Description An attacker can use XSS (in color parameter IceWarp WebMail and before)to send a malicious script to an unsuspecting Admins or users. The end admins or useras browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session # tokens, or other sensitive information retained by the browser and used # with that site. These scripts can even rewrite the content of the HTML # page. Even an attacker can easily place users in social engineering through # this vulnerability and create a fake field.
Reference N/A
URL Link
