CVE-2021-27182

HIGH

Altn Mdaemon < 20.0.4 - Injection

Title source: rule
STIX 2.1

Description

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.altn.com/Support/SecurityUpdate/MD011221_MDaemon_EN/

Scores

CVSS v3 8.8
EPSS 0.0086
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
altn/mdaemon < 20.0.4
Published Apr 14, 2021
Tracked Since Feb 18, 2026