Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-03T17:27:42

Updated: 2024-08-04T14:08:29.664Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-18724

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-02-03T18:15:16.100

Modified: 2021-02-25T19:59:34.933

Link: CVE-2020-18724

cve-icon Redhat

No data.