CVE-2025-34490

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Configurations

No configuration.

History

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Las versiones anteriores a la 21.8 de GFI MailEssentials son vulnerables a un problema de entidad externa XML (XXE). Un atacante remoto autenticado puede enviar solicitudes HTTP manipuladas para leer archivos arbitrarios del sistema.

28 Apr 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-28 19:15

Updated : 2025-04-29 13:52


NVD link : CVE-2025-34490

Mitre link : CVE-2025-34490

CVE.ORG link : CVE-2025-34490


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference