578
VMScore

CVE-2021-27182

Published: 14/04/2021 Updated: 21/04/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in MDaemon prior to 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an malicious user to perform any action with the privileges of the attacked user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Github Repositories

MDaemon Advisories - CVE-2021-27180, CVE-2021-27181, CVE-2021-27182, CVE-2021-27183

MDaemon-Advisories MDaemon Advisories: CVE-2021-27180 (Reflected XSS) CVE-2021-27181 (CSRF Token Fixation) CVE-2021-27182 (Iframe injection) CVE-2021-27183 (Remote Code Execution) Those vulnerabilities were already patched on January 2021 and are published for CVE purposes They can be chained to achieve RCE/Account Takeover over email message (user interaction requir