MailEnable Reflected Cross-Site Scripting Vulnerability in AddressBook.aspx

Vulnerability

A reflected cross-site scripting vulnerability has been identified in MailEnable versions prior to 10.54. The issue resides in the FieldBcc parameter of the AddressBook.aspx page. The vulnerability arises because the FieldBcc value is not adequately sanitized when processed through a GET request. This unsanitized input is reflected within a <script> block in a JavaScript variable, allowing remote attackers to execute arbitrary JavaScript in the context of the victim's browser during email composition. Exploitation of this vulnerability could lead to redirection to malicious sites, theft of non-HttpOnly cookies, injection of arbitrary HTML or CSS, and execution of actions as the authenticated user.

Impact

Exploitation allows for the execution of arbitrary JavaScript in the victim's browser, potentially leading to cookie theft, injection of malicious HTML or CSS, and execution of actions as the authenticated user.

Remediation

Users can update to MailEnable version 10.54 or later to address this vulnerability.

Added: Dec 9, 2025, 11:03 PM
Updated: Dec 9, 2025, 11:03 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.5
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.