Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-39598 PoC — IceWarp WebClient 跨站脚本漏洞

Source
Associated Vulnerability
Title:IceWarp WebClient 跨站脚本漏洞 (CVE-2023-39598)
Description:Icewarp IceWarp WebClient是捷克爱思华宝(Icewarp)公司的一款基于web的邮件服务客户端。 IceWarp WebClient v.10.2.1 版本存在安全漏洞,该漏洞源于远程攻击者通过精心构造的有效负载(payload)执行任意代码,该有效负载将传递给mid参数。
Description
Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.
File Snapshot

id: CVE-2023-39598 info: name: IceWarp Email Client - Cross Site Scripting author: Imjust0 se ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.