CVE-2025-34490
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
MEDIUM · CVSS 6.5
EPSS 0.00133
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0