Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Alt-N MDaemon: CVE-2024-11182: Improper Neutralization of Input During Web Page Generation

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Nov 15, 2024
Added
May 20, 2025
Modified
May 21, 2025

Description

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c.
An attacker can send an HTML e-mail message with JavaScript in an img tag.
This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

Solution

alt-n-mdaemon-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.