CVE-2024-11182 is a Cross-Site Scripting (XSS) vulnerability affecting MDaemon Email Server versions prior to 24.5.1c. An attacker can exploit this by sending a specially crafted HTML email containing JavaScript within an img tag, allowing arbitrary JavaScript execution in a webmail user's browser. This vulnerability has a CVSS score of 6.1 (MEDIUM) due to its network-based attack vector, low attack complexity, and potential for partial confidentiality and integrity impact. Critically, this CVE is actively exploited in the wild, as indicated by its inclusion in the KEV catalog and significant media coverage detailing its use in espionage campaigns. While no public Metasploit or Nuclei modules exist, the high FAUCET Risk Score and extensive community discussion highlight its severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 24.5.0CPE match | cpe:2.3:a:mdaemon:email_server:*:*:*:*:*:*:*:* | ||
< 24.5.1CPE matchmatch criteria | cpe:2.3:a:mdaemon:mdaemon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.