cve/2025/CVE-2025-3929.md
2025-09-29 21:09:30 +02:00

1.0 KiB

CVE-2025-3929

Description

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window, and access user data.

POC

Reference

No PoCs from references.

Github