Back to search
CVE-2025-40631
Published: May 16, 2025
Modified: May 16, 2025
PUBLISHED
Description
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.
| Vendor | Product | Versions |
|---|---|---|
Icewarp | Icewarp Mail Server | affected 11.4.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now