Record summary

CVE-2025-44148 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 3, 2025 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubbarisbaydur/CVE-2025-44148Repository PoCby barisbaydurStars: 3Not analyzed1 file

763 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMMailEnable Mail Service < v10 - Cross-Site ScriptingCVSS 5.4

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component.

Impact

Attackers can execute arbitrary JavaScript in victim browsers through the state parameter in failure.aspx, potentially leading to session hijacking and credential theft.

Remediation

Upgrade to MailEnable version 10 or later that properly sanitizes user input in the failure.aspx component.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2025xssmailenablevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Shodan: title:"MailEnable"
FOFA: title="MailEnable"

Source: ProjectDiscovery

References

3