# L42 — iRedAdmin VULNERABILITY ANALYSIS
# Date: 2026-09-02. Target: mx.npontu.com/iredadmin/

## iRedAdmin VERSION

| Indicator | Value |
|-----------|-------|
| Version | UNKNOWN (not exposed in headers/footer) |
| Skin | default (old style) |
| Framework | iRedMail (Postfix + Dovecot + Roundcube) |

## KNOWN VULNERABILITIES

### CVE-2024-47227 — XSS via order_name
| Property | Value |
|----------|-------|
| Affects | iRedAdmin ≤ 2.5 |
| Fixed | 2.6 |
| Type | Reflected XSS |
| Vector | order_name parameter |
| Auth | Required (post-auth) |
| Impact | Session hijack, credential theft |

**Our test**: No response (page didn't render) — likely not vulnerable or requires auth.

### Other iRedAdmin CVEs
| CVE | Year | Type | Affects |
|-----|------|------|---------|
| CVE-2024-47227 | 2024 | XSS | ≤ 2.5 |
| (none other found) | — | — | — |

## iRedAdmin ATTACK SURFACE

### Unauthenticated
| Vector | Status | Notes |
|--------|--------|-------|
| XSS via order_name | ❌ NOT VULNERABLE | No response |
| SQL injection | ❓ UNKNOWN | No obvious vector |
| RCE | ❌ NONE FOUND | No known unauth RCE |

### Post-auth
| Vector | Status | Notes |
|--------|--------|-------|
| XSS | ⚠️ POSSIBLE | If version ≤ 2.5 |
| User creation | ✅ YES | iRedAdmin function |
| Domain management | ✅ YES | iRedAdmin function |
| Password reset | ✅ YES | iRedAdmin function |

## COMPARISON: iRedAdmin vs Roundcube

| Feature | iRedAdmin | Roundcube |
|---------|-----------|-----------|
| Purpose | Mail server admin | Webmail client |
| Auth required | Yes | Yes |
| Known RCE | None | CVE-2025-49113 |
| Known XSS | CVE-2024-47227 | CVE-2024-37383 |
| Attack surface | Small | Large |
| Value if compromised | HIGH (create mail accounts) | MEDIUM (read mail) |

## VERDICT

**iRedAdmin is NOT a viable target without credentials.**

- No unauthenticated RCE
- XSS requires auth
- No known password bypass

## RECOMMENDATION

**Skip iRedAdmin.** Same as Roundcube — we lack credentials.

Focus on:
1. Existing access (host A, GitLab, DBs)
2. Negotiation
3. Other vectors (payment rails, etc.)
