Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.
| Software | From | Fixed in |
|---|---|---|
| merak / mail_server | 8.0.3 | 8.0.3.x |
| icewarp / web_mail | 5.4.2 | 5.4.2.x |