VendorsIceWarpmail_server10.4.5
Vulnerabilities

IceWarp Mail Server 10.4.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-39699
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.
Published 2023-08-24 · Modified
9.8EPSS 0.014
CVE-2023-39700
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
Published 2023-08-24 · Modified
6.1EPSS 0.015