CVE-2025-34399

Publication date

2025-12-09 18:10:08

Family

VulnCheck

State

PUBLISHED

Description

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a