MailEnable, Reflected Cross-Site Scripting, CVE-2025-34398 (Medium)

Listen to this Post

MailEnable versions prior to 10.54 contain a reflected cross-site scripting vulnerability in the AddressesBcc parameter of the AddressBook.aspx page. The vulnerability arises when the application processes GET requests without proper input sanitization. The AddressesBcc parameter value is directly reflected within a

Scroll to Top