CVE-2020-18723
Summary
| CVE | CVE-2020-18723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-03 18:15:00 UTC |
| Updated | 2021-02-25 17:17:00 UTC |
| Description | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Altn | Mdaemon Webmail | All | All | All | All |
| Application | Altn | Mdaemon Webmail | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alt-N MDaemon Webmail 20.0.0 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Stored Cross Site Scripting on Mdaemon Webmail (20.0.0) – Kailash | MISC | kailashbohara.com.np | Exploit, Third Party Advisory |
| MDaemon Patch Bulletin – MD082520 | MISC | www.altn.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.