← Back

CVE-2025-3929

nvd nist
Published: Apr 29, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@eset.com (Secondary)

Description

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.

Affected (9)

1 product
Email Server
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Mdaemon
From 20.0.0 to 20.0.9
From 21.0.0 to 21.0.8
From 21.5.0 to 21.5.6
From 22.0.0 to 22.0.7
From 23.0.0 to 23.0.4
From 23.5.0 to 23.5.5
From 24.0.0 to 24.0.4
From 24.5.0 to 24.5.3
From 25.0.0 to 25.0.2

References (1)

Source: security@eset.com
Release Notes

Timeline

No history available yet.