vendor:
IceWarp Web Mail
by:
Unknown
7.5
CVSS
HIGH
Input Validation
20
CWE
Product Name: IceWarp Web Mail
Affected Version From: All versions prior to 5.2.8
Affected Version To: 5.2.2008
Patch Exists: YES
Related CWE:
CPE: a:icewarp:icewarp_web_mail:5.2.7
Platforms Tested:
Unknown
IceWarp Web Mail Multiple Input Validation Vulnerabilities
Multiple input validation vulnerabilities in IceWarp Web Mail allow remote attackers to conduct SQL Injection, Account Manipulation, Cross-site Scripting, Information disclosure, Local file system access, and other attacks.
Mitigation:
Upgrade to IceWarp Web Mail version 5.2.8 or later.