Junglewise Threat Intelligence

CVE-2024-11182: MDaemon Email Server XSS in HTML email messages

CVE-2024-11182 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2025-05-19

Executive brief

MDaemon Email Server, a popular alternative to Microsoft Exchange for business email, is vulnerable to a security flaw that allows attackers to run malicious code in a user's web browser. By sending a specially crafted email, an attacker can execute scripts when the recipient views the message in their webmail interface. This could lead to the theft of login credentials, unauthorized access to email accounts, or the hijacking of active user sessions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in MDaemon Email Server versions prior to 24.5.1c. The flaw is rooted in the improper sanitization of HTML email content, specifically within 'img' tags. A remote, unauthenticated attacker can exploit this by sending a crafted email containing malicious JavaScript. When a victim views the email through the MDaemon webmail interface, the script executes in the context of the user's browser session. This can be used to steal session cookies, perform actions on behalf of the user, or redirect the user to malicious websites. This vulnerability has been observed being exploited in the wild.

Affected products

  • MDaemon MDaemon Email Server before 24.5.1c

Timeline

  • 2024-11-15: disclosed: Initial NVD publication
  • 2024-11-15: patched: Fixed in version 24.5.1c
  • 2025-05-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog