Vulnerabilities
22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37242 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2022-29976 +1 in the same advisory: …29975 | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2022-25356 | Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection. Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection. NVD description · AI analysis pending | 5.3 | 6% | PoC |
| — | |
| CVE-2021-27182 | An issue was discovered in MDaemon before 20.0.4. An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user. NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2020-18723 +1 in the same advisory: …18724 | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwar Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities. NVD description · AI analysis pending | 5.4 | 4% | PoC ×2 |
| — | |
| CVE-2019-19497 | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-17792 | MDaemon Webmail (formerly WorldClient) has CSRF. MDaemon Webmail (formerly WorldClient) has CSRF. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2019-13612 | MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special c MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2019-8984 +1 in the same advisory: …8983 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2). MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2). NVD description · AI analysis pending | 6.1 | <1% |
| — |