CVE-2025-14499
Unknown Unknown - Not Provided
Cross-Site Scripting in IceWarp gmaps Enables Authentication Bypass

Publication date: 2025-12-23

Last updated on: 2025-12-23

Assigner: Zero Day Initiative

Description
IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a parameter passed to the gmaps webpage. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25441.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-23
Last Modified
2025-12-23
Generated
2026-05-07
AI Q&A
2025-12-24
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
icewarp gmaps *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in IceWarp gmaps allows remote attackers to bypass authentication by exploiting improper validation of a parameter passed to the gmaps webpage. It involves injecting arbitrary scripts (Cross-Site Scripting) that can lead to authentication bypass when a user interacts by visiting a malicious page or opening a malicious file.


How can this vulnerability impact me? :

The vulnerability can allow attackers to bypass authentication on affected IceWarp installations, potentially giving them unauthorized access to the system. This can lead to full compromise, including confidentiality, integrity, and availability impacts.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart