Vulnerability Description
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
CVSS Score
6.1
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Icewarp | Icewarp Server | < 13.0.1.2 |
| Icewarp | Mail Server | < 13.0.1.2 |
Related Weaknesses (CWE)
References
- http://icewarp.comProduct
- http://mail.ziyan.comPermissions Required
- https://medium.com/%40rohitgautam26/cve-2021-36580-69219798231c
- http://icewarp.comProduct
- http://mail.ziyan.comPermissions Required
- https://medium.com/%40rohitgautam26/cve-2021-36580-69219798231c
FAQ
What is CVE-2021-36580?
CVE-2021-36580 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
How severe is CVE-2021-36580?
CVE-2021-36580 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36580?
Check the references section above for vendor advisories and patch information. Affected products include: Icewarp Icewarp Server, Icewarp Mail Server.