CVE Database
/

CVE-2025-40631

Back to search

CVE-2025-40631

Published: May 16, 2025

Modified: May 16, 2025

PUBLISHED

Description

HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.

VendorProductVersions

Icewarp

Icewarp Mail Server

affected
11.4.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now