578
VMScore

CVE-2021-27183

Published: 14/04/2021 Updated: 21/04/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in MDaemon prior to 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new files in any location of the filesystem, or he may be able to modify existing files. This vulnerability may directly lead to Remote Code Execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Github Repositories

MDaemon Advisories - CVE-2021-27180, CVE-2021-27181, CVE-2021-27182, CVE-2021-27183

MDaemon-Advisories MDaemon Advisories: CVE-2021-27180 (Reflected XSS) CVE-2021-27181 (CSRF Token Fixation) CVE-2021-27182 (Iframe injection) CVE-2021-27183 (Remote Code Execution) Those vulnerabilities were already patched on January 2021 and are published for CVE purposes They can be chained to achieve RCE/Account Takeover over email message (user interaction requir