PT-2024-16805 · Unknown · Mdaemon Email Server

Matthieu Faou

·

Published

2024-11-15

·

Updated

2026-05-02

·

CVE-2024-11182

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MDaemon Email Server versions prior to 24.5.1c
Description A Cross-Site Scripting (XSS) issue exists where a remote attacker can send an HTML email containing JavaScript within an img tag. This allows the attacker to load arbitrary JavaScript code in the context of a webmail user's browser window. This flaw has been actively exploited by the Russia-linked APT28 group in Operation RoundPress, targeting government and defense organizations across Eastern Europe, Africa, and South America to steal credentials and emails.
Recommendations Update to version 24.5.1c or later.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-07577
CVE-2024-11182

Affected Products

Mdaemon Email Server