Vulnerability Details CVE-2025-34399
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable var sAddrCc. By supplying a crafted payload that terminates the existing LoadCurAddresses() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-34399
-
cpe:2.3:a:mailenable:mailenable:10.00
-
cpe:2.3:a:mailenable:mailenable:10.10
-
cpe:2.3:a:mailenable:mailenable:10.11
-
cpe:2.3:a:mailenable:mailenable:10.12
-
cpe:2.3:a:mailenable:mailenable:10.13
-
cpe:2.3:a:mailenable:mailenable:10.14
-
cpe:2.3:a:mailenable:mailenable:10.15
-
cpe:2.3:a:mailenable:mailenable:10.16
-
cpe:2.3:a:mailenable:mailenable:10.17
-
cpe:2.3:a:mailenable:mailenable:10.18
-
cpe:2.3:a:mailenable:mailenable:10.19
-
cpe:2.3:a:mailenable:mailenable:10.20
-
cpe:2.3:a:mailenable:mailenable:10.21
-
cpe:2.3:a:mailenable:mailenable:10.22
-
cpe:2.3:a:mailenable:mailenable:10.23
-
cpe:2.3:a:mailenable:mailenable:10.24
-
cpe:2.3:a:mailenable:mailenable:10.25
-
cpe:2.3:a:mailenable:mailenable:10.26
-
cpe:2.3:a:mailenable:mailenable:10.27
-
cpe:2.3:a:mailenable:mailenable:10.28
-
cpe:2.3:a:mailenable:mailenable:10.29
-
cpe:2.3:a:mailenable:mailenable:10.30
-
cpe:2.3:a:mailenable:mailenable:10.31
-
cpe:2.3:a:mailenable:mailenable:10.32
-
cpe:2.3:a:mailenable:mailenable:10.33
-
cpe:2.3:a:mailenable:mailenable:10.34
-
cpe:2.3:a:mailenable:mailenable:10.35
-
cpe:2.3:a:mailenable:mailenable:10.36
-
cpe:2.3:a:mailenable:mailenable:10.37
-
cpe:2.3:a:mailenable:mailenable:10.38
-
cpe:2.3:a:mailenable:mailenable:10.39
-
cpe:2.3:a:mailenable:mailenable:10.40
-
cpe:2.3:a:mailenable:mailenable:10.41
-
cpe:2.3:a:mailenable:mailenable:10.42
-
cpe:2.3:a:mailenable:mailenable:10.43
-
cpe:2.3:a:mailenable:mailenable:8.00
-
cpe:2.3:a:mailenable:mailenable:8.01
-
cpe:2.3:a:mailenable:mailenable:8.02
-
cpe:2.3:a:mailenable:mailenable:8.03
-
cpe:2.3:a:mailenable:mailenable:8.04
-
cpe:2.3:a:mailenable:mailenable:8.50
-
cpe:2.3:a:mailenable:mailenable:8.51
-
cpe:2.3:a:mailenable:mailenable:8.52
-
cpe:2.3:a:mailenable:mailenable:8.53
-
cpe:2.3:a:mailenable:mailenable:8.54
-
cpe:2.3:a:mailenable:mailenable:8.55
-
cpe:2.3:a:mailenable:mailenable:8.56
-
cpe:2.3:a:mailenable:mailenable:8.57
-
cpe:2.3:a:mailenable:mailenable:8.58
-
cpe:2.3:a:mailenable:mailenable:8.59
-
cpe:2.3:a:mailenable:mailenable:8.60
-
cpe:2.3:a:mailenable:mailenable:8.61
-
cpe:2.3:a:mailenable:mailenable:8.62
-
cpe:2.3:a:mailenable:mailenable:8.63
-
cpe:2.3:a:mailenable:mailenable:8.64
-
cpe:2.3:a:mailenable:mailenable:8.65
-
cpe:2.3:a:mailenable:mailenable:8.66
-
cpe:2.3:a:mailenable:mailenable:8.67
-
cpe:2.3:a:mailenable:mailenable:9.0
-
cpe:2.3:a:mailenable:mailenable:9.01
-
cpe:2.3:a:mailenable:mailenable:9.02
-
cpe:2.3:a:mailenable:mailenable:9.03
-
cpe:2.3:a:mailenable:mailenable:9.04
-
cpe:2.3:a:mailenable:mailenable:9.05
-
cpe:2.3:a:mailenable:mailenable:9.10
-
cpe:2.3:a:mailenable:mailenable:9.11
-
cpe:2.3:a:mailenable:mailenable:9.12
-
cpe:2.3:a:mailenable:mailenable:9.13
-
cpe:2.3:a:mailenable:mailenable:9.14
-
cpe:2.3:a:mailenable:mailenable:9.15
-
cpe:2.3:a:mailenable:mailenable:9.16
-
cpe:2.3:a:mailenable:mailenable:9.17
-
cpe:2.3:a:mailenable:mailenable:9.18
-
cpe:2.3:a:mailenable:mailenable:9.50
-
cpe:2.3:a:mailenable:mailenable:9.51
-
cpe:2.3:a:mailenable:mailenable:9.52
-
cpe:2.3:a:mailenable:mailenable:9.53
-
cpe:2.3:a:mailenable:mailenable:9.54
-
cpe:2.3:a:mailenable:mailenable:9.60
-
cpe:2.3:a:mailenable:mailenable:9.61
-
cpe:2.3:a:mailenable:mailenable:9.62
-
cpe:2.3:a:mailenable:mailenable:9.70
-
cpe:2.3:a:mailenable:mailenable:9.71
-
cpe:2.3:a:mailenable:mailenable:9.72
-
cpe:2.3:a:mailenable:mailenable:9.73
-
cpe:2.3:a:mailenable:mailenable:9.74
-
cpe:2.3:a:mailenable:mailenable:9.75
-
cpe:2.3:a:mailenable:mailenable:9.76
-
cpe:2.3:a:mailenable:mailenable:9.77
-
cpe:2.3:a:mailenable:mailenable:9.78
-
cpe:2.3:a:mailenable:mailenable:9.79
-
cpe:2.3:a:mailenable:mailenable:9.80
-
cpe:2.3:a:mailenable:mailenable:9.81
-
cpe:2.3:a:mailenable:mailenable:9.82
-
cpe:2.3:a:mailenable:mailenable:9.83
-
cpe:2.3:a:mailenable:mailenable:9.84
-
cpe:2.3:a:mailenable:mailenable:9.85
-
cpe:2.3:a:mailenable:mailenable:9.86