ZeroHour

CVE-2020-18723

PoC ×2
CVSS 3.1
5.4 medium
EPSS
4%p89
Published
()
Modified
Description

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

Vendors
altn
Products
mdaemon webmail
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.