PT-2026-6592 · Unknown · Axigen Mail Server

CVE-2025-68643

·

Published

2026-02-05

·

Updated

2026-02-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Axigen Mail Server versions prior to 10.5.57
Description The software contains a stored Cross-Site Scripting (XSS) issue in how it handles the timeFormat account preference parameter. An attacker can leverage this by injecting a malicious JavaScript payload into the timeFormat preference. When a victim logs into the WebMail interface, the unsanitized timeFormat value is loaded and inserted into the Document Object Model (DOM), leading to script execution. This requires a multi-stage attack, potentially involving exploiting a separate issue or using compromised credentials to initially inject the payload.
Recommendations Update to version 10.5.57 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68643

Affected Products

Axigen Mail Server