CVE-2024-11182: MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
An XSS issue was discovered in
MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker
to load arbitrary JavaScript code in the context of a webmail user's browser window.
Other sources
MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MDaemon Email Serverto a version that resolves this vulnerability.Fixed in 24.5.1c - Compensating control
If vendor mitigations are unavailable, discontinue use of MDaemon Email Server; for cloud deployments follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11182?
CVE-2024-11182 is classified as a medium severity vulnerability due to its potential to allow XSS attacks.
How do I fix CVE-2024-11182?
To mitigate CVE-2024-11182, update MDaemon Email Server to version 24.5.1c or later.
What type of vulnerability is CVE-2024-11182?
CVE-2024-11182 is an XSS (Cross-Site Scripting) vulnerability that exploits HTML email messages.
Who is affected by CVE-2024-11182?
MDaemon Email Server users running versions prior to 24.5.1c are affected by CVE-2024-11182.
What can an attacker do with CVE-2024-11182?
An attacker can execute arbitrary JavaScript code in a webmail user's browser, potentially compromising user data.