CVE-2020-18724: Altn MDaemon Webmail
Medium severity, CVSS 5.4. EPSS: 3.2% chance of exploitation in the next 30 days.
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
Affected products
- Altn MDaemon Webmail: before 20.0.1 (fixed in 20.0.1)
Published 2021-02-03. Last modified 2026-06-17.