GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-14684 GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 07:30:00 +0900


Wed, 05 Nov 2025 03:00:00 +0900

Type Values Removed Values Added
Title GFI MailEssentials XXE Vulnerability GFI MailEssentials < 21.8 XXE Arbitrary File Read

Sat, 10 May 2025 10:15:00 +0900

Type Values Removed Values Added
First Time appeared Gfi
Gfi mailessentials
CPEs cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:*
Vendors & Products Gfi
Gfi mailessentials

Tue, 29 Apr 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 04:15:00 +0900

Type Values Removed Values Added
Description GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Title GFI MailEssentials XXE Vulnerability
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-19T01:26:14.676Z

Reserved: 2025-04-15T19:15:22.611Z

Link: CVE-2025-34490

cve-icon Vulnrichment

Updated: 2025-04-28T19:43:53.842Z

cve-icon NVD

Status : Modified

Published: 2025-04-28T19:15:47.050

Modified: 2025-11-04T23:15:36.927

Link: CVE-2025-34490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses