CVE-2024-11182
Unknown Unknown - Not Provided

BaseFortify

Vulnerability report for CVE-2024-11182, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2024-11-15

Last updated on: 2025-10-30

Assigner: ESET

Description

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2024-11-15
Last Modified
2025-10-30
Generated
2026-09-27
AI Q&A
2024-11-15
EPSS Evaluated
2026-09-25
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mdaemon mdaemon to 24.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability, identified as CVE-2024-11182, is a type of security issue known as Cross-Site Scripting (XSS) found in MDaemon Email Server before version 24.5.1c. It allows an attacker to send an email that contains harmful JavaScript code. When a user opens this email in their webmail, the malicious code can run in their browser, potentially allowing the attacker to manipulate the user's session or steal information.

Impact Analysis

If you use MDaemon Email Server and have not updated to version 24.5.1c or later, you could be at risk. An attacker could send you a specially crafted email that, when opened, executes harmful JavaScript in your browser. This could lead to unauthorized access to your personal information or allow the attacker to perform actions on your behalf without your consent.

Compliance Impact

This vulnerability could potentially impact compliance with regulations like GDPR and HIPAA because it may lead to unauthorized access to personal data. If an attacker successfully exploits this vulnerability and gains access to sensitive information, it could result in a data breach, which is a violation of these regulations. Organizations must ensure their systems are secure to protect user data and maintain compliance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-11182. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart