CVE-2025-34490
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 28, 2025
Updated: May 10, 2025
CWE ID 611
Summary
CVE-2025-34490 refers to a vulnerability affecting GFI MailEssentials versions below 21.8. This issue involves an XML External Entity (XXE) problem, making it possible for authenticated, remote attackers to craft and send malicious HTTP requests, resulting in the reading of arbitrary system files. This vulnerability can pose a significant risk to system security and integrity. It is highly recommended for users to upgrade to the latest version of GFI MailEssentials to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.