CVE-2020-18724: XSS
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-18724?
CVE-2020-18724 is an authenticated stored cross-site scripting (XSS) vulnerability in the contact name field in the distribution list of MDaemon webmail 19.5.5.
What is the severity of CVE-2020-18724?
CVE-2020-18724 has a severity of medium with a CVSS severity score of 5.4.
How does CVE-2020-18724 affect Altn Mdaemon Webmail?
CVE-2020-18724 affects Altn Mdaemon Webmail version up to and excluding 20.0.1.
How can an attacker exploit CVE-2020-18724?
An attacker can exploit CVE-2020-18724 by executing malicious code and performing a cross-site scripting (XSS) attack while opening a contact list.
How can I fix the CVE-2020-18724 vulnerability?
To fix the CVE-2020-18724 vulnerability, upgrade MDaemon webmail to a version equal to or newer than 20.0.1.