CVE-2025-40632

Severity CVSS v4.0:
LOW
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/05/2025
Last modified:
09/10/2025

Description

Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:icewarp:mail_server:11.4.0:*:*:*:*:*:*:*