Code injection in MDaemon - CVE-2021-27182
Published: June 14, 2023
MDaemon
Alt-N
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation when processing email messages in Webmail WorldClient. A remote attacker can send a specially crafted HTML email with injected iframe and gain access to sensitive information or perform spoofing attack.