VYPR
Medium severity6.1NVD Advisory· Published Apr 14, 2021· Updated Jun 17, 2026

CVE-2021-27180

CVE-2021-27180

Description

An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Alt N/Mdaemon2 versions
    cpe:2.3:a:altn:mdaemon:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:altn:mdaemon:*:*:*:*:*:*:*:*range: <20.0.4
    • (no CPE)range: <20.0.4
  • MDaemon/MDaemon Webmaildescription
  • Alt N/Webmailllm-create
    Range: <20.0.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.