Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40630


Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.


Published

2025-05-16T11:15:44.763

Last Modified

2025-10-09T19:32:14.100

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icewarp mail_server 11.4.0 Yes

References