An XSS issue was discovered in
MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message
with
JavaScript in an img tag. This could
allow a remote attacker
to load arbitrary JavaScript code in the context of a webmail user's browser window.
🚨 Marked as known exploited on May 19th, 2025 (12 days ago).
CVE ID: CVE-2024-11182
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vendor: MDaemon
Product: Email Server
EPSS Score: 39.83% (probability of being exploited)
EPSS Percentile: 97.13% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)
SSVC Exploitation: active
SSVC Technical Impact: partial
SSVC Automatable: false