Reflected Cross-Site Scripting Vulnerability in MailEnable by MailEnable
CVE-2025-34425
What is CVE-2025-34425?
MailEnable versions before 10.54 are susceptible to a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the WindowContext parameter in the /Mondo/lang/sys/Forms/MAI/compose.aspx endpoint. The vulnerability allows attackers to exploit crafted GET requests, injecting malicious JavaScript into the victim's browser via the window.location context. This can lead to unauthorized actions, including redirecting users to harmful sites and potentially stealing session cookies or other sensitive information. Users are advised to upgrade to protected versions to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MailEnable 0 < 10.54
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
