CVE-2025-34490
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Affected (1)
Products: Gfi: Mailessentials
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.8 |
References (3)
Source: disclosure@vulncheck.com
Exploit
Source: disclosure@vulncheck.com
Release Notes
Source: disclosure@vulncheck.com
Timeline
No history available yet.