CVE-2026-23614: GFI MailEssentials AI < 22.4 Anti-Spam Sender Policy Framework IP Exceptions Description Stored XSS
GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv2$txtIPDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23614?
CVE-2026-23614 is classified as a medium severity stored cross-site scripting vulnerability.
How do I fix CVE-2026-23614?
To fix CVE-2026-23614, upgrade GFI MailEssentials AI to version 22.4 or later.
Who is affected by CVE-2026-23614?
CVE-2026-23614 affects GFI MailEssentials AI versions prior to 22.4.
What kind of attack is possible with CVE-2026-23614?
CVE-2026-23614 allows authenticated users to inject HTML/JavaScript through the Sender Policy Framework IP Exceptions interface.
What are the potential impacts of CVE-2026-23614?
Exploitation of CVE-2026-23614 could lead to unauthorized actions being performed or data being stolen from the affected system.