Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15436 Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.
Fixes

Solution

The vulnerabilities have been fixed by the IceWarp team in the 13.0.2 version.


Workaround

No workaround given by the vendor.

History

Thu, 09 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Icewarp
Icewarp mail Server
CPEs cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:*
Vendors & Products Icewarp
Icewarp mail Server
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 16 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 11:15:00 +0000

Type Values Removed Values Added
Description Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.
Title Open redirection vulnerability in IceWarp Mail Server
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-16T13:46:17.479Z

Reserved: 2025-04-16T08:38:09.208Z

Link: CVE-2025-40630

cve-icon Vulnrichment

Updated: 2025-05-16T13:15:58.165Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-16T11:15:44.763

Modified: 2025-10-09T19:32:14.100

Link: CVE-2025-40630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.