GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Metrics
Affected Vendors & Products
References
History
Sat, 10 May 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gfi
Gfi mailessentials |
|
CPEs | cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gfi
Gfi mailessentials |
Mon, 28 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files. | |
Title | GFI MailEssentials XXE Vulnerability | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-04-28T19:02:03.532Z
Updated: 2025-04-28T19:44:01.442Z
Reserved: 2025-04-15T19:15:22.611Z
Link: CVE-2025-34490

Updated: 2025-04-28T19:43:53.842Z

Status : Analyzed
Published: 2025-04-28T19:15:47.050
Modified: 2025-05-10T00:58:59.130
Link: CVE-2025-34490

No data.