SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-18723

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

MEDIUM 5.4EPSS 3.80%

Does this matter?

Lower severity and a low EPSS score (3.80%). Track it; it rarely justifies an emergency change on its own.

Description

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
3.80% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
altn/mdaemon webmail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.