PT-2025-50367 · Mailenable · Mailenable

Mushroomsecteam

·

Published

2025-12-10

·

Updated

2025-12-15

·

CVE-2025-34428

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MailEnable versions prior to 10.54
Description MailEnable versions prior to 10.54 store user and administrative passwords in plaintext within the AUTH.SAV file, which has overly permissive filesystem access. A local authenticated user with read access to this file can recover all user passwords and super-admin credentials. These credentials can then be used to authenticate to MailEnable services such as POP3, SMTP, or the webmail interface, enabling unauthorized mailbox access and administrative control.
Recommendations Update MailEnable to version 10.54 or later.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-34428

Affected Products

Mailenable