ZeroHour

CVE-2021-27182

PoC
CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

Vendors
altn
Products
mdaemon
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.