S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-12593 Scanner

CVE-2019-12593 scanner - Local File Inclusion (LFI) vulnerability in IceWarp Mail Server

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-12593
7.5
CVSS

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

IceWarp Mail Server is a software application that enables organizations to manage their emails, contacts, calendars, and tasks. It is widely used in corporations, non-profit organizations, and government agencies. The product offers several features like anti-virus and anti-spam protection, mobile synchronization, secure collaboration, and backup and recovery services.

Recently, a vulnerability has been detected in IceWarp Mail Server, identified by the CVE-2019-12593 code. This vulnerability is classified as a local file inclusion (LFI) vulnerability, which allows an attacker to execute arbitrary code or access sensitive information stored in the server. The vulnerability is caused by a directory traversal that occurs in the webmail/calendar/minimizer/index.php?style=..%5c URL.

If this vulnerability is exploited, an attacker can access critical data stored on the server, which includes email messages, contact lists, calendar appointments, and other sensitive information. This can lead to data theft, identity theft, financial loss, and reputational damage for organizations that use this software.

Thanks to the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive vulnerability scanning, penetration testing, and security audit services that can help organizations mitigate cybersecurity risks and protect their digital assets from potential threats. By using the platform, organizations can ensure that their infrastructure is secure and resilient against any cyber attack.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations should take the following precautions:

  • Install the latest patches and updates provided by IceWarp Mail Server.
  • Disable the webmail/calendar/minimizer/index.php?style=..%5c URL or restrict access to authorized users only.
  • Implement a secure coding practice to prevent directory traversal attacks.
  • Set up a logging and monitoring system to detect any suspicious activity.
  • Conduct regular vulnerability assessments and penetration testing to identify any other security weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.