VYPR

Mdaemon Webmail

by Alt N

CVEs (3)

  • CVE-2018-17792HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.01

    MDaemon Webmail (formerly WorldClient) has CSRF.

  • CVE-2020-18724MedFeb 3, 2021
    risk 0.38cvss 5.4epss 0.03

    Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

  • CVE-2020-18723MedFeb 3, 2021
    risk 0.38cvss 5.4epss 0.04

    Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.