CVE-2025-3929
29.04.2025, 12:15
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
Vendor | Product | Version |
---|---|---|
mdaemon | email_server | 20.0.0 ≤ 𝑥 < 20.0.9 |
mdaemon | email_server | 21.0.0 ≤ 𝑥 < 21.0.8 |
mdaemon | email_server | 21.5.0 ≤ 𝑥 < 21.5.6 |
mdaemon | email_server | 22.0.0 ≤ 𝑥 < 22.0.7 |
mdaemon | email_server | 23.0.0 ≤ 𝑥 < 23.0.4 |
mdaemon | email_server | 23.5.0 ≤ 𝑥 < 23.5.5 |
mdaemon | email_server | 24.0.0 ≤ 𝑥 < 24.0.4 |
mdaemon | email_server | 24.5.0 ≤ 𝑥 < 24.5.3 |
mdaemon | email_server | 25.0.0 ≤ 𝑥 < 25.0.2 |
𝑥
= Vulnerable software versions