Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15434 Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Fixes

Solution

The vulnerabilities have been fixed by the IceWarp team in the 13.0.2 version.


Workaround

No workaround given by the vendor.

History

Thu, 09 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Icewarp
Icewarp mail Server
CPEs cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:*
Vendors & Products Icewarp
Icewarp mail Server
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 16 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 May 2025 11:15:00 +0000

Type Values Removed Values Added
Description Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Title Cross-site scripting (XSS) vulnerability in IceWarp Mail Server
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-05-16T13:46:48.664Z

Reserved: 2025-04-16T08:38:09.209Z

Link: CVE-2025-40632

cve-icon Vulnrichment

Updated: 2025-05-16T13:15:08.486Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-16T11:15:45.847

Modified: 2025-10-09T19:31:29.610

Link: CVE-2025-40632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.