Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-14064 PoC — IceWarp Mail Server 安全漏洞

Source
Associated Vulnerability
Title:IceWarp Mail Server 安全漏洞 (CVE-2020-14064)
Description:Icewarp IceWarp Mail Server是捷克爱思华宝(Icewarp)公司的一款邮件服务器产品。该产品支持电子邮件归档、SmartAttach附件、自动迁移等。 IceWarp Mail Server 12.3.0.1版本存在安全漏洞,该漏洞源于程序没有正确对用户帐户进行访问控制。
Readme
# Icewarp Email Server 12.3.0.1 incorrect_access_control
https://nvd.nist.gov/vuln/detail/CVE-2020-14064

## Introduction :
### first step:  Login to your account and then send request to delete whole inbox and capture this request with Burp suit. (security is attacker account)
![alt text](https://github.com/networksecure/Icewarp_incorrect_access_control/blob/master/incorrect1.png)

### second step: Sniff your local network, may be your office and find a ice warp account and its SID.

### third step:  Replace your SID and username with victim SID and username and then send the request. (security2 is victim account)
![alt text](https://github.com/networksecure/Icewarp_incorrect_access_control/blob/master/incorrect2.png)

result: victim's Inbox has been deleted.
File Snapshot

[4.0K] /data/pocs/8618623dba684849396c1cb9a4f33a425c70ab97 ├── [ 94K] incorrect1.png ├── [124K] incorrect2.png └── [ 771] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.