PT-2025-50366 · Mailenable · Mailenable

Mushroomsecteam

·

Published

2025-12-10

·

Updated

2025-12-15

·

CVE-2025-34427

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MailEnable versions prior to 10.54
Description MailEnable versions prior to 10.54 store user and administrative passwords in plaintext within the AUTH.TAB file, which has overly permissive filesystem access. A local authenticated user with read access to this file can recover all user passwords and super-admin credentials. These credentials can then be used to authenticate to MailEnable services such as POP3, SMTP, or the webmail interface, potentially enabling unauthorized mailbox access and administrative control.
Recommendations Update MailEnable to version 10.54 or later.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34427

Affected Products

Mailenable