CVE-2020-25925: Icewarp Webclient
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
Affected products
- Icewarp Webclient: version 10.3.5 only
Published 2021-07-07. Last modified 2026-06-17.