CVE-2025-34425 - MailEnable < 10.54 Reflected XSS in WindowContext Parameter of MAI/compose.aspx
CVE ID : CVE-2025-34425
Published : Dec. 9, 2025, 10:16 p.m. | 59 minutes ago
Description : MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The WindowContext value is not properly sanitized when processed via a GET request and is reflected within a
Published : Dec. 9, 2025, 10:16 p.m. | 59 minutes ago
Description : MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The WindowContext value is not properly sanitized when processed via a GET request and is reflected within a