Reflected Cross-Site Scripting Vulnerability in MailEnable Email Software
CVE-2025-34401
What is CVE-2025-34401?
MailEnable versions prior to 10.54 have a vulnerability in the FieldBcc parameter of the Address Book management interface, which is susceptible to reflected cross-site scripting (XSS) attacks. The vulnerability arises from improper sanitization of user input in the FieldBcc value during GET requests. This flaw allows an attacker to inject malicious scripts that are executed in the context of the victim's browser, particularly during email composition. Successful attacks could redirect users to harmful sites, extract non-HttpOnly cookies, and inject arbitrary HTML or CSS, potentially allowing the attacker to perform actions on behalf of authenticated users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MailEnable 0 < 10.54
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
