Description
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.
Affected products
- alt-n / mdaemon8.1.3 – 8.1.3
- alt-n / worldclient8.1.3 – 8.1.3