CVE-2025-34490

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 28, 2025
Updated: May 10, 2025
CWE ID 611

Summary

CVE-2025-34490 refers to a vulnerability affecting GFI MailEssentials versions below 21.8. This issue involves an XML External Entity (XXE) problem, making it possible for authenticated, remote attackers to craft and send malicious HTTP requests, resulting in the reading of arbitrary system files. This vulnerability can pose a significant risk to system security and integrity. It is highly recommended for users to upgrade to the latest version of GFI MailEssentials to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share