PT-2025-50367 · Mailenable · Mailenable

Mushroomsecteam

·

Publicado

2025-12-10

·

Atualizado

2025-12-15

·

CVE-2025-34428

CVSS v4.0

8.4

Alta

VetorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MailEnable versions prior to 10.54
Description MailEnable versions prior to 10.54 store user and administrative passwords in plaintext within the AUTH.SAV file, which has overly permissive filesystem access. A local authenticated user with read access to this file can recover all user passwords and super-admin credentials. These credentials can then be used to authenticate to MailEnable services such as POP3, SMTP, or the webmail interface, enabling unauthorized mailbox access and administrative control.
Recommendations Update MailEnable to version 10.54 or later.

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-34428

Produtos afetados

Mailenable