CVE-2025-3929: Stored XSS vulnerability in MDaemon Email Server
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3929?
CVE-2025-3929 is classified as a medium severity vulnerability due to its potential for exploitation through XSS attacks.
How do I fix CVE-2025-3929?
To fix CVE-2025-3929, update MDaemon Email Server to version 25.0.2 or later.
Who is affected by CVE-2025-3929?
CVE-2025-3929 affects users of MDaemon Email Server versions 25.0.1 and below.
What kind of attack does CVE-2025-3929 facilitate?
CVE-2025-3929 facilitates cross-site scripting (XSS) attacks by allowing the execution of JavaScript in the user's webmail browser.
What can attackers exploit in CVE-2025-3929?
Attackers can exploit CVE-2025-3929 by sending specially crafted HTML e-mails containing malicious JavaScript within img tags.