ZeroHour

CVE-2025-44148

PoC large

Unauthenticated XSS in MailEnable failure.aspx enabling arbitrary code execution

CVSS 3.1
9.8 critical
EPSS
55%p99
Published
()
Modified
AI analysis

MailEnable, a Windows-based mail server platform, contains a cross-site scripting flaw (CWE-79) in its failure.aspx web component in all versions before v10. A remote, unauthenticated attacker can deliver crafted input to failure.aspx, causing attacker-controlled script or code to execute in the context of the affected web interface; notably, the CVSS 9.8 vector requires neither privileges nor user interaction and rates confidentiality, integrity, and availability impact as high. Per the advisory, successful exploitation allows arbitrary code execution, which in a webmail context typically translates to session hijacking, credential theft, or actions taken on behalf of logged-in users. Any organization running MailEnable prior to v10 is affected, with the greatest risk where the webmail/web interface is exposed to the internet. A public proof-of-concept exists on GitHub; the issue is not yet in CISA KEV, but EPSS of 54.7% (99th percentile) indicates an elevated likelihood of exploitation within 30 days.

What to do: Upgrade all MailEnable deployments to v10 or later, as versions before v10 are affected. Where upgrading is not immediately possible, restrict or gate internet-facing access to the MailEnable webmail/web interface and monitor requests to failure.aspx for crafted or unusual input. Given the public PoC and high EPSS score, prioritize this patch and review internet exposure of any Windows hosting servers running MailEnable.

Affected
MailEnable (failure.aspx component)all versions before v10
Estimated exposure
large≈10,000–100,000 deployed MailEnable servers, many internet-exposed — MailEnable is one of the most widely deployed Windows mail servers, historically bundled with Plesk on Windows hosting stacks, and public internet-wide scans have shown tens of thousands of exposed MailEnable hosts, placing realistic…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

Vendors
mailenable
Products
mailenable
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.