Ashish Dhone ./blog

Jul 2, 2026 · 15 min read · 4 views

One Parameter. One Payload. Another CVE — XSS in IceWarp WebClient Calendar (CVE-2020-25925)

By Ashish Dhone (@ashketchum) · CVE Research · Published April 2021

Ashish Dhone

Ashish Dhone

Offensive Security Researcher

How a single unsanitized URL parameter in a webmail calendar handed me my second CVE


By Ashish Dhone (@ashketchum) · CVE Research · Published April 2021

🔒 Subscriber Only

Continue reading for $5/month

Get full access to this post and every future write-up — bug bounty reports, red teaming guides, and offensive security deep-dives.

Supports USD & INR · Cancel anytime

2 reads

⚡ Enjoy this write-up?

Get every post like this — $5/month

Bug bounty reports, red teaming guides, and offensive security write-ups. New content every week. Cancel anytime.

Subscribe now →

Supports in USD & INR · Secure checkout via Dodo Payments

Want personalised guidance?

Book a 1-on-1 strategy call with me — offensive security, red teaming, SOC career path, or breaking into cybersecurity.

Book a session on Topmate →