Description
IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or other unintended redirects.
IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or other unintended redirects.
id: CVE-2021-36580
info:
name: IceWarp Mail Server - Open Redirect
author: DhiyaneshDk
severity: medium
description: |
IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or other unintended redirects.
impact: |
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
remediation: |
Apply the latest security patches or updates provided by IceWarp to fix the open redirect vulnerability.
reference:
- https://www.icewarp.com/
- https://twitter.com/shifacyclewala/status/1443298941311668227
- http://icewarp.com
- http://mail.ziyan.com
- https://medium.com/%40rohitgautam26/cve-2021-36580-69219798231c
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2021-36580
cwe-id: CWE-601
epss-score: 0.01588
epss-percentile: 0.74367
cpe: cpe:2.3:a:icewarp:icewarp_server:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: icewarp
product: icewarp_server
shodan-query:
- title:"icewarp"
- http.title:"icewarp"
fofa-query: title="icewarp"
google-query: intitle:"icewarp"
tags: cve2021,cve,icewarp,redirect,vuln
http:
- method: GET
path:
- "{{BaseURL}}/webmail/basic/?referer=https://interact.sh&_c=auth&ctz=120&signup_password=&_a%5bsignup%5d=1"
matchers:
- type: regex
part: header
regex:
- '(?m)^(?:Location\s*?:\s*?)(?:https?:\/\/|\/\/|\/\\\\|\/\\)(?:[a-zA-Z0-9\-_\.@]*)interact\.sh\/?(\/|[^.].*)?$' # https://regex101.com/r/L403F0/1
# digest: 490a00463044022049d4fc2fd773aad411b2209604cd22de921c5677b77b9546813c78b2b91f2652022012050d7e5a3bb8008b64bc4544e73cd9031975f1255f0510d042fffac9d771c9:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.