Back to Database
Status published
Medium
CVE-2010-5340
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST...
Vulnerability Description
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-5340
Credits & Attribution
No credits recorded in the NVD database.
References
More from icewarp
View All →CVE-2022-35115
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was...
Critical
9.8
CVE-2021-36580
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep...
Medium
6.1
CVE-2020-8512
In IceWarp Webmail Server through 11.4.4.1, there is XSS in...
Medium
6.1
CVE-2020-27982
IceWarp 11.4.5.0 allows XSS via the language parameter....
Medium
6.1
CVE-2020-25925
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient...
Medium
6.1
Affected Vendor
icewarp
View all reports →Affected Software
webclient
Vulnerable Versions:
10.0
Timeline
Official Publish:
October 11th, 2019
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.