CVE-2020-18723 describes a stored cross-site scripting (XSS) vulnerability in MDaemon webmail versions prior to 19.5.5. This flaw allows an authenticated attacker to inject malicious code into the file attachment field, which then executes on the email recipient's side when an email is forwarded, potentially leading to unauthorized actions. With a CVSS score of 5.4 (Medium), the vulnerability requires user interaction and low privileges, but can result in limited confidentiality and integrity impacts. While not listed in CISA's KEV catalog or having Metasploit/Nuclei modules, an ExploitDB entry exists for a similar XSS in a later version, indicating potential exploitability. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.0.1CPE matchmatch criteria | cpe:2.3:a:altn:mdaemon_webmail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.