Cross-site scripting (XSS) vulnerability in IceWarp Mail Server
Vulnerability Description
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40632
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Julen Garrido Estévez
References
Affected Vendor
Icewarp
View all reports →