CVE-2021-27182

HIGH

MDaemon < 20.0.4 - IFRAME Injection in Webmail via Email Message

Title source: llm
STIX 2.1

Description

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.altn.com/Support/SecurityUpdate/MD011221_MDaemon_EN/

Scores

CVSS v3 8.8
EPSS 0.0155
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
altn/mdaemon < 20.0.4
Published Apr 14, 2021
Tracked Since Feb 18, 2026