Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-11182

67
FAUCET Score

CVE-2024-11182 is a Cross-Site Scripting (XSS) vulnerability affecting MDaemon Email Server versions prior to 24.5.1c. An attacker can exploit this by sending a specially crafted HTML email containing JavaScript within an img tag, allowing arbitrary JavaScript execution in a webmail user's browser. This vulnerability has a CVSS score of 6.1 (MEDIUM) due to its network-based attack vector, low attack complexity, and potential for partial confidentiality and integrity impact. Critically, this CVE is actively exploited in the wild, as indicated by its inclusion in the KEV catalog and significant media coverage detailing its use in espionage campaigns. While no public Metasploit or Nuclei modules exist, the high FAUCET Risk Score and extensive community discussion highlight its severe threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 24.5.0CPE match
cpe:2.3:a:mdaemon:email_server:*:*:*:*:*:*:*:*
< 24.5.1CPE matchmatch criteria
cpe:2.3:a:mdaemon:mdaemon:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
17.11%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · May 19, 2025
This CVE's current EPSS score of 0.1711 is in the 99th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
files.mdaemon.com / mdaemon/beta/RelNotes_en.html
Release Notes