GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
History

Mon, 28 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Description GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Title GFI MailEssentials XXE Vulnerability
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-04-28T19:02:03.532Z

Updated: 2025-04-28T19:44:01.442Z

Reserved: 2025-04-15T19:15:22.611Z

Link: CVE-2025-34490

cve-icon Vulnrichment

Updated: 2025-04-28T19:43:53.842Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-28T19:15:47.050

Modified: 2025-04-29T13:52:10.697

Link: CVE-2025-34490

cve-icon Redhat

No data.