← back
CVE-2025-34490mediumCWE-611

GFI MailEssentials < 21.8 XXE Arbitrary File Read

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
In short

GFI MailEssentials before version 21.8 has a flaw that lets authenticated attackers read any file on the server by sending specially crafted XML requests. This is dangerous because sensitive files like passwords or configuration data could be exposed.

Technical detail

The application fails to properly validate XML input, allowing XXE injection attacks. An authenticated remote attacker can leverage this vulnerability by submitting malicious XML payloads to access arbitrary files on the underlying system, potentially disclosing sensitive configuration, credentials, or other confidential data.

Summary generated and translated by AI from the official description.
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
GFI · MailEssentials