Skip to content
COOEY

EXPOSURES › CVE-2024-11182

CVE-2024-11182

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-11182 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

MDaemon XSS allowed remote code execution in HTML emails

MDaemon Email Server had an unpatched XSS vulnerability that enabled remote attackers to execute arbitrary JavaScript code through HTML emails, leading to potential data breaches and unauthorized access.

Shame score — Critical vulnerability actively exploited with no patch available.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.