CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-3929

MEDIUM
5.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-04-29
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.

Affected Platforms (CPE)

📦
Mdaemon

Email Server

>= 20.0.0 and < 20.0.9>= 21.0.0 and < 21.0.8>= 21.5.0 and < 21.5.6>= 22.0.0 and < 22.0.7>= 23.0.0 and < 23.0.4>= 23.5.0 and < 23.5.5>= 24.0.0 and < 24.0.4>= 24.5.0 and < 24.5.3>= 25.0.0 and < 25.0.2

References & Advisories

関連する脆弱性情報