Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mailenable
Mailenable mailenable |
|
| CPEs | cpe:2.3:a:mailenable:mailenable:*:*:*:*:standard:*:*:* | |
| Vendors & Products |
Mailenable
Mailenable mailenable |
|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var fieldTo. By supplying a crafted payload that terminates the existing Finish() function, inserts attacker-controlled script, and comments out remaining code, a remote attacker can execute arbitrary JavaScript in a victim’s browser when the victim attempts to send an email. Successful exploitation can redirect victims to malicious sites, steal non-HttpOnly cookies, inject arbitrary HTML or CSS, and perform actions as the authenticated user. | |
| Title | MailEnable < 10.54 Reflected XSS in FieldTo Parameter of AddressBook.aspx | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-09T20:36:15.858Z
Reserved: 2025-04-15T19:15:22.598Z
Link: CVE-2025-34403
Updated: 2025-12-09T20:12:21.292Z
Status : Analyzed
Published: 2025-12-09T18:15:50.820
Modified: 2025-12-09T21:34:24.623
Link: CVE-2025-34403
No data.
OpenCVE Enrichment
No data.