Home

Description

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the SelectedIndex parameter in the ManageShares.aspx form, which is not properly sanitized before being embedded into dynamically generated JavaScript.

PUBLISHED Reserved 2026-03-16 | Published 2026-03-23 | Updated 2026-05-11 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

Any version before 10.55.0
affected

Credits

Egidio Romano finder

References

www.mailenable.com/...urce=RSSADMIN&ID=MAILENABLEVERSION1055 vendor-advisory patch

karmainsecurity.com/KIS-2026-05 technical-description exploit

mailenable.com/Standard-ReleaseNotes.txt release-notes

www.mailenable.com/ product

www.vulncheck.com/...nageshares-aspx-selectedindex-parameter third-party-advisory

cve.org (CVE-2026-32850)

nvd.nist.gov (CVE-2026-32850)

Download JSON