ZeroHour

CVE-2025-34490

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p51
Published
()
Modified
Description

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.

Vendors
gfi
Products
mailessentials
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.