Back to Database
Status published
Critical
CVE-2022-35115
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was...
Vulnerability Description
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-35115
Credits & Attribution
No credits recorded in the NVD database.
References
More from icewarp
View All →CVE-2021-36580
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep...
Medium
6.1
CVE-2020-8512
In IceWarp Webmail Server through 11.4.4.1, there is XSS in...
Medium
6.1
CVE-2020-27982
IceWarp 11.4.5.0 allows XSS via the language parameter....
Medium
6.1
CVE-2020-25925
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient...
Medium
6.1
CVE-2020-14066
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript...
High
8.8
Affected Vendor
icewarp
View all reports →Affected Software
webclient dc2
Vulnerable Versions:
13.0.2.9
Timeline
Official Publish:
August 23rd, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.