CVE-2024-11182 – Stored XSS vulnerability in MDaemon Email Server
https://notcve.org/view.php?id=CVE-2024-11182
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window. Se descubrió un problema de XSS en MDaemon Email Server anterior a la versión 24.5.1c. Un atacante puede enviar un mensaje de correo electrónico HTML con JavaScript en una etiqueta img. • https://files.mdaemon.com/mdaemon/beta/RelNotes_en.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-52269
https://notcve.org/view.php?id=CVE-2023-52269
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators. MDaemon SecurityGateway hasta 9.0.3 permite XSS a través de una regla de filtrado de contenido de mensajes manipulada. Esto podría permitir a los administradores de dominio realizar ataques contra administradores globales. • https://github.com/vipercalling/XSSsecurityGateway/blob/main/finding https://mdaemon.com/pages/security-gateway • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2002-1739
https://notcve.org/view.php?id=CVE-2002-1739
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords. • http://online.securityfocus.com/archive/1/271374 http://www.securityfocus.com/bid/4686 https://exchange.xforce.ibmcloud.com/vulnerabilities/9025 • CWE-326: Inadequate Encryption Strength •