CVE-2021-27180: XSS
An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows performing any action with the privileges of the attacked user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-27180?
CVE-2021-27180 is a vulnerability discovered in MDaemon before version 20.0.4 that allows for Reflected XSS in Webmail, also known as WorldClient.
How can CVE-2021-27180 be exploited?
CVE-2021-27180 can be exploited through a GET request in MDaemon Webmail (WorldClient).
What is the severity of CVE-2021-27180?
CVE-2021-27180 has a severity rating of 6.1 (medium).
What is the affected software for CVE-2021-27180?
The affected software for CVE-2021-27180 is MDaemon before version 20.0.4.
Is there a security update available for CVE-2021-27180?
Yes, a security update is available. Please refer to the following link: [https://www.altn.com/Support/SecurityUpdate/MD011221_MDaemon_EN/](https://www.altn.com/Support/SecurityUpdate/MD011221_MDaemon_EN/)