CVE-2024-11182: MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

Medium severity, CVSS 6.1. Actively exploited: in CISA KEV since 2025-05-19. EPSS: 17.6% chance of exploitation in the next 30 days.

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

Affected products

  • MDaemon MDaemon: before 24.5.1 (fixed in 24.5.1)

Published 2024-11-15. Last modified 2026-06-17.