MailEnable Reflected Cross-Site Scripting Vulnerability in Webmail Compose Feature

Vulnerability

A reflected cross-site scripting vulnerability has been identified in MailEnable versions prior to 10.54. The issue resides in the Message parameter of the /Mobile/Compose.aspx page, where input is not properly sanitized before being reflected into a JavaScript context via a GET request. This vulnerability allows remote attackers to execute arbitrary JavaScript in the context of the victim's browser by crafting a reply URL that injects malicious scripts. Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, such as stealing non-HttpOnly cookies, injecting harmful HTML or CSS, or redirecting the user to malicious websites.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute JavaScript in the context of the user's browser.

Added: Dec 9, 2025, 11:05 PM
Updated: Dec 9, 2025, 11:05 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.5
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.