VendorsAltnmdaemon_webmailall versions
Vulnerabilities

Altn Mdaemon Webmail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-17792
MDaemon Webmail (formerly WorldClient) has CSRF.
Published 2019-07-19 · Modified
8.8EPSS 0.010
CVE-2020-18723
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.
Published 2021-02-03 · Modified
5.41 PoCEPSS 0.038
CVE-2020-18724
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
Published 2021-02-03 · Modified
5.41 PoCEPSS 0.032