CVE-2025-34490

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:mailessentials:*:*:*:*:*:*:*:*

History

10 May 2025, 00:58

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-28 19:15

Updated : 2025-05-10 00:58


NVD link : CVE-2025-34490

Mitre link : CVE-2025-34490

CVE.ORG link : CVE-2025-34490


JSON object : View

Products Affected

gfi

  • mailessentials
CWE
CWE-611

Improper Restriction of XML External Entity Reference