Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-03T17:27:42

Updated: 2021-02-08T18:06:19

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-18724

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-03T18:15:16.100

Modified: 2021-02-25T19:59:34.933


Link: CVE-2020-18724

JSON object: View

cve-icon Redhat Information

No data.

CWE