Loading
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.
Use CWE-79, Icewarp vendor hub and Mail Server product page to widen CVE-2025-40632 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39699, CVE-2020-14066 and CVE-2020-14065 for nearby disclosures in the same product family.