Description
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version before 21.8
Credits
Frycos
References
frycos.github.io/vulns4free/2025/04/28/mailessentials.html
gfi.ai/...ssentials/resources/documentation/product-releases
www.vulncheck.com/...-mailessentials-xxe-arbitrary-file-read