Reflected Cross-Site Scripting Vulnerability in MailEnable by MailEnable
CVE-2025-34406
What is CVE-2025-34406?
MailEnable versions prior to 10.54 are susceptible to a reflected cross-site scripting (XSS) vulnerability stemming from the improper sanitization of the Id parameter in the /Mobile/ContactDetails.aspx page. When crafted payloads are sent via GET requests, the response reflects unfiltered data within a block, allowing attackers to execute arbitrary JavaScript in the context of the victim's browser. This exploitation can lead to various malicious activities including the redirection to harmful sites, theft of session cookies, and injection of unwarranted HTML or CSS, ultimately compromising the integrity of the authenticated user's session.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MailEnable 0 < 10.54
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
