← Back

CVE-2025-68723

nvd nist
Published: Feb 5, 2026Modified: Feb 13, 2026

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Exploitability: 2.3 / Impact: 6.0
Source: NVD

Description

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File name parameter in the WebMail Listeners SSL settings. Attackers can inject malicious JavaScript payloads that execute in administrators' browsers when they access affected pages or features, enabling privilege escalation attacks where low-privileged admins can force high-privileged admins to perform unauthorized actions.

Affected (2)

1 product
Axigen Mail Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Axigen
From 10.3.0 to 10.5.57
From 10.6.0 to 10.6.26

Timeline

No history available yet.