EUVD-2025-15434
ID: EUVD-2025-15434
Severity: low
CVSS v4: 2.0 (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N)
CVSS v3: Not provided
CWE: None listed
Source: ENISA
Description
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Timestamps
- Normalized:
- Last updated:
References
No references provided.