CVE-2025-34490: GFI MailEssentials < 21.8 XXE Arbitrary File Read
Published Apr 28, 2025
·Updated
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
Affected Software
2 affected components
GFI MailEssentials<21.8
GFI MailEssentials<21.8
Event History
Apr 28, 2025
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-34490?
CVE-2025-34490 is classified as a medium severity vulnerability due to its potential for data exposure through XML External Entity (XXE) attacks.
2
How do I fix CVE-2025-34490?
To resolve CVE-2025-34490, upgrade GFI MailEssentials to version 21.8 or later.
3
What type of attack can exploit CVE-2025-34490?
CVE-2025-34490 can be exploited through crafted HTTP requests that trigger XML External Entity (XXE) vulnerabilities.
4
Who is affected by CVE-2025-34490?
CVE-2025-34490 affects users of GFI MailEssentials versions prior to 21.8.
5
What can an attacker do with CVE-2025-34490?
An authenticated and remote attacker can exploit CVE-2025-34490 to read arbitrary system files on the server.