Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14281 | An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data. |
| Link | Providers |
|---|---|
| https://mdaemon.com/pages/downloads-critical-updates |
|
Mon, 12 May 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mdaemon
Mdaemon email Server |
|
| CPEs | cpe:2.3:a:mdaemon:email_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mdaemon
Mdaemon email Server |
|
| Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Apr 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data. | |
| Title | Stored XSS vulnerability in MDaemon Email Server | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ESET
Published:
Updated: 2025-04-29T13:19:29.916Z
Reserved: 2025-04-25T06:32:08.202Z
Link: CVE-2025-3929
Updated: 2025-04-29T13:19:25.858Z
Status : Analyzed
Published: 2025-04-29T12:15:32.300
Modified: 2025-05-12T19:35:32.720
Link: CVE-2025-3929
No data.
OpenCVE Enrichment
No data.
EUVD