[ autentificare ] [ înregistrare ] [ Restabilire ]
Contactează-ne
Ne puteți contacta prin:
0day.today   exploit-uri Market și 0day exploit-uri Database

Alt-N MDaemon webmail 20.0.0 - (Contact name) Stored Cross Site Scripting Vulnerability

Autor
Kailash Bohara
Risc
[
Nivel de securitate mediu
]
0day-ID
0day-ID-35793
Categorie
web applications
Data
08-02-2021
CVE
CVE-2020-18724
Platformă
windows
# Exploit Title: Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
# Exploit Author: Kailash Bohara
# Vendor Homepage: https://www.altn.com/
# Version: Mdaemon webmail < 20.0.0
# CVE : 2020-18724

1. Go to contact section and distribution list menu. Create a new distribution list.
2. Contact name field is vulnerabile to XSS. Use the payload <img src=x onerror=alert(1)>
3. We can see execution code and after saving it, each time we visits the distribution list section the XSS pop-up is seen.

#  0day.today [2024-07-01]  #