Back

HIGH

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability

Published Oct 11, 2019

Description

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 11, 2019
Updated Aug 7, 2024
Reserved Oct 11, 2019
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a