PT-2024-16805 · Unknown · Mdaemon Email Server
Matthieu Faou
·
Published
2024-11-15
·
Updated
2026-05-02
·
CVE-2024-11182
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MDaemon Email Server versions prior to 24.5.1c
Description
A Cross-Site Scripting (XSS) issue exists where a remote attacker can send an HTML email containing JavaScript within an
img tag. This allows the attacker to load arbitrary JavaScript code in the context of a webmail user's browser window. This flaw has been actively exploited by the Russia-linked APT28 group in Operation RoundPress, targeting government and defense organizations across Eastern Europe, Africa, and South America to steal credentials and emails.Recommendations
Update to version 24.5.1c or later.
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mdaemon Email Server