CVE-2025-68723

CRITICAL

Axigen Mail Server 10.3.0-10.5.57 - Stored Cross-Site Scripting in WebAdmin Interface

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-68723. PoCs published by osmancanvural.

AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2025-68723, a Stored XSS vulnerability in Axigen WebAdmin. It includes specific payloads, affected components, and steps to reproduce the exploit, demonstrating a clear understanding of the vulnerability mechanics.

Description

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) the Certificate File name parameter in the WebMail Listeners SSL settings. Attackers can inject malicious JavaScript payloads that execute in administrators' browsers when they access affected pages or features, enabling privilege escalation attacks where low-privileged admins can force high-privileged admins to perform unauthorized actions.

Exploits (1)

nomisec WRITEUP
by osmancanvural · poc
https://github.com/osmancanvural/CVE-2025-68723

The repository provides a detailed technical analysis of CVE-2025-68723, a Stored XSS vulnerability in Axigen WebAdmin. It includes specific payloads, affected components, and steps to reproduce the exploit, demonstrating a clear understanding of the vulnerability mechanics.

Classification
Writeup 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Axigen WebAdmin < 10.6.26
Auth required
Prerequisites: Low-privileged administrator access · Ability to inject payload into log files or SSL certificates
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.0
EPSS 0.0026
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
axigen/axigen_mail_server 10.3.0 - 10.5.57
Published Feb 05, 2026
Tracked Since Feb 18, 2026