CVE-2025-44148
PoC largeUnauthenticated XSS in MailEnable failure.aspx enabling arbitrary code execution
MailEnable, a Windows-based mail server platform, contains a cross-site scripting flaw (CWE-79) in its failure.aspx web component in all versions before v10. A remote, unauthenticated attacker can deliver crafted input to failure.aspx, causing attacker-controlled script or code to execute in the context of the affected web interface; notably, the CVSS 9.8 vector requires neither privileges nor user interaction and rates confidentiality, integrity, and availability impact as high. Per the advisory, successful exploitation allows arbitrary code execution, which in a webmail context typically translates to session hijacking, credential theft, or actions taken on behalf of logged-in users. Any organization running MailEnable prior to v10 is affected, with the greatest risk where the webmail/web interface is exposed to the internet. A public proof-of-concept exists on GitHub; the issue is not yet in CISA KEV, but EPSS of 54.7% (99th percentile) indicates an elevated likelihood of exploitation within 30 days.
What to do: Upgrade all MailEnable deployments to v10 or later, as versions before v10 are affected. Where upgrading is not immediately possible, restrict or gate internet-facing access to the MailEnable webmail/web interface and monitor requests to failure.aspx for crafted or unusual input. Given the public PoC and high EPSS score, prioritize this patch and review internet exposure of any Windows hosting servers running MailEnable.
| MailEnable (failure.aspx component) | all versions before v10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
- Vendors
- mailenable
- Products
- mailenable
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.