cognitive cybersecurity intelligence

News and Analysis

Search

CISA Adds MDaemon Email Server XSS Vulnerability to KEV Catalog Following Exploitation

CISA Adds MDaemon Email Server XSS Vulnerability to KEV Catalog Following Exploitation

CISA has added a critical vulnerability, CVE-2024-11182, affecting MDaemon Email Server to its Known Exploited Vulnerabilities Catalog. This XSS flaw allows attackers to execute harmful JavaScript via infected HTML emails, risking user sessions. MDaemon has issued a patch for affected versions. Organizations must apply updates promptly or consider disabling the vulnerable service.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts