Total vulnerabilities in the database
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
Software | From | Fixed in |
---|---|---|
mdaemon / email_server | 20.0.0 | 20.0.9 |
mdaemon / email_server | 21.0.0 | 21.0.8 |
mdaemon / email_server | 21.5.0 | 21.5.6 |
mdaemon / email_server | 22.0.0 | 22.0.7 |
mdaemon / email_server | 23.0.0 | 23.0.4 |
mdaemon / email_server | 23.5.0 | 23.5.5 |
mdaemon / email_server | 24.0.0 | 24.0.4 |
mdaemon / email_server | 24.5.0 | 24.5.3 |
mdaemon / email_server | 25.0.0 | 25.0.2 |