Aller au contenu

Fiche vulnérabilité

CVE-2021-27182 : faille élevée altn mdaemon (CVSS 8.8)

Description

An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
14 avr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • altn mdaemon

Références

Rechercher une autre vulnérabilité dans la base CVE