S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-39598 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in IceWarp WebClient affects v. 10.2.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-39598
6.1
CVSS

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The IceWarp Corporation WebClient is an email client that allows users to securely access their email accounts from anywhere in the world. It is designed for users seeking an intuitive interface with a wealth of features, including email management, calendar synchronizations, and chat capabilities. 

However, security researchers have reported a critical vulnerability in the IceWarp WebClient that could jeopardize the security of data stored in the email client. The vulnerability has been identified as CVE-2023-39598, and it enables remote attackers to execute arbitrary code via a crafted payload to the mid parameter. 

When exploited, the CVE-2023-39598 vulnerability can lead to severe consequences, including data theft, privacy invasion, denial-of-service attacks, and financial loss. An attacker can deploy a malicious JavaScript code in the mid parameter, causing the user's browser to execute it without their knowledge or consent. This can lead to the theft of sensitive information, such as login credentials, credit card details, and other personal data. 

At s4e.io, we are committed to providing pro-level security measures for our clients. By using our platform, readers of this article can quickly and easily learn about vulnerabilities in their digital assets, and take proactive measures to prevent them. Our advanced security features, including real-time monitoring and threat detection, help ensure that your valuable data is secured from malicious attacks. By relying on s4e.io, you can focus on your business, while we take care of your security needs.

 

REFERENCES

Solution Advice

To protect against the CVE-2023-39598 vulnerability, users of the IceWarp WebClient can take the following precautions:

  • Keep the IceWarp WebClient software up-to-date with the latest patches and security updates.
  • Use a reliable antivirus software to detect and prevent malware attacks.
  • Disable or limit the use of JavaScript in the email client.
  • Avoid clicking on links and opening attachments from unknown senders.
  • Use strong, unique passwords for all online accounts, including the IceWarp WebClient. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-39598 scanner - Cross-Site Scripting (XSS) vulnerability in IceWarp WebClient | S4E