CVEs Blog | G5 Cyber Security

CVE-2020-25925 – Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.

Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the “p4” field.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25925

Reference (s):

Exit mobile version