# Icewarp Email Server 12.3.0.1 incorrect_access_control
https://nvd.nist.gov/vuln/detail/CVE-2020-14064
## Introduction :
### first step: Login to your account and then send request to delete whole inbox and capture this request with Burp suit. (security is attacker account)

### second step: Sniff your local network, may be your office and find a ice warp account and its SID.
### third step: Replace your SID and username with victim SID and username and then send the request. (security2 is victim account)

result: victim's Inbox has been deleted.
[4.0K] /data/pocs/8618623dba684849396c1cb9a4f33a425c70ab97
├── [ 94K] incorrect1.png
├── [124K] incorrect2.png
└── [ 771] README.md
0 directories, 3 files