Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39699


IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.


Published

2023-08-25T00:15:09.283

Last Modified

2024-11-21T08:15:50.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icewarp mail_server 10.4.5 Yes

References