GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files. | |
Title | GFI MailEssentials XXE Vulnerability | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-04-28T19:02:03.532Z
Updated: 2025-04-28T19:44:01.442Z
Reserved: 2025-04-15T19:15:22.611Z
Link: CVE-2025-34490

Updated: 2025-04-28T19:43:53.842Z

Status : Awaiting Analysis
Published: 2025-04-28T19:15:47.050
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-34490

No data.