← Back

CVE-2025-34490

nvd nist
Published: Apr 28, 2025Modified: Nov 4, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.

Affected (1)

Products: Gfi: Mailessentials
1 product
Mailessentials
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 21.8

Timeline

No history available yet.