Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Oct 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Icewarp
Icewarp mail Server |
|
CPEs | cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:* | |
Vendors & Products |
Icewarp
Icewarp mail Server |
|
Metrics |
cvssV3_1
|
Fri, 16 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 16 May 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered. | |
Title | Cross-site scripting (XSS) vulnerability in IceWarp Mail Server | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-16T13:46:48.664Z
Reserved: 2025-04-16T08:38:09.209Z
Link: CVE-2025-40632

Updated: 2025-05-16T13:15:08.486Z

Status : Analyzed
Published: 2025-05-16T11:15:45.847
Modified: 2025-10-09T19:31:29.610
Link: CVE-2025-40632

No data.

No data.