HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Fixes

Solution

The vulnerabilities have been fixed by the IceWarp team in the 13.0.2 version.


Workaround

No workaround given by the vendor.

History

Fri, 16 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 11:15:00 +0000

Type Values Removed Values Added
Description HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
Title HTTP host header injection vulnerability in IceWarp Mail Server
Weaknesses CWE-644
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-16T13:46:34.760Z

Reserved: 2025-04-16T08:38:09.209Z

Link: CVE-2025-40631

cve-icon Vulnrichment

Updated: 2025-05-16T13:15:30.500Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-16T11:15:45.690

Modified: 2025-05-16T14:42:18.700

Link: CVE-2025-40631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.