CVE-2024-0246
Icewarp
CVE-2024-0246: Cross-site scripting (XSS) vulnerability in IceWarp. A problematic vulnerability has been discovered in IceWarp versions 12.0.2.1 and 12.0.3.1, specifically affecting the Utility Download Handler component at /install/
. By manipulating the lang
argument with a crafted input, a remote attacker can inject malicious scripts and execute a cross-site scripting attack. The exploit code is publicly available, making exploitation easier. Although the CVSS score is 6.1, SOCRadar's Vulnerability Risk Score (SVRS) is 58, indicating a moderate risk. Even though not critical (SVRS > 80), administrators should apply appropriate security measures. The lack of vendor response to disclosure further elevates concern and emphasizes the importance of proactive mitigation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.