CVE-2026-23615: GFI MailEssentials AI < 22.4 Anti-Spam Sender Policy Framework Email Exceptions Description Stored XSS
GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv4$txtEmailDescription parameter to /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23615?
CVE-2026-23615 is classified as a medium severity stored cross-site scripting vulnerability.
How do I fix CVE-2026-23615?
To fix CVE-2026-23615, upgrade GFI MailEssentials AI to version 22.4 or later.
Who is affected by CVE-2026-23615?
GFI MailEssentials AI users with versions prior to 22.4 are affected by CVE-2026-23615.
What vulnerabilities does CVE-2026-23615 exploit?
CVE-2026-23615 exploits a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions interface.
Is authentication required to exploit CVE-2026-23615?
Yes, an authenticated user is required to exploit CVE-2026-23615.