← Back to CVE List
CVE-2025-3929NVD
Vulnerability Summary
An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Mdaemon Email Server >= 20.0.0 and < 20.0.9
- Mdaemon Email Server >= 21.0.0 and < 21.0.8
- Mdaemon Email Server >= 21.5.0 and < 21.5.6
- Mdaemon Email Server >= 22.0.0 and < 22.0.7
- Mdaemon Email Server >= 23.0.0 and < 23.0.4
- Mdaemon Email Server >= 23.5.0 and < 23.5.5
- Mdaemon Email Server >= 24.0.0 and < 24.0.4
- Mdaemon Email Server >= 24.5.0 and < 24.5.3
- Mdaemon Email Server >= 25.0.0 and < 25.0.2
- Mdaemon Email Server 20.0.9
- Mdaemon Email Server 21.0.8
- Mdaemon Email Server 21.5.6
- Mdaemon Email Server 22.0.7
- Mdaemon Email Server 23.0.4
- Mdaemon Email Server 23.5.5
- Mdaemon Email Server 24.0.4
- Mdaemon Email Server 24.5.3
- Mdaemon Email Server 25.0.2