ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-3929
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below.

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.

NVD description · AI analysis pending
5.3<1%
  • mdaemon email server
CVE-2024-11182
Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail

MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers.

Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date.

5.318% KEV
  • MDaemon Technologies MDaemon Email Server all versions before 24.5.1c
moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users
CVE-2023-52269
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule.

MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.

NVD description · AI analysis pending
4.8<1% PoC
  • mdaemon securitygateway