PT-2026-6592 · Unknown · Axigen Mail Server

Published

2026-02-05

·

Updated

2026-02-11

·

CVE-2025-68643

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Axigen Mail Server versions prior to 10.5.57
Description The software contains a stored Cross-Site Scripting (XSS) issue in how it handles the timeFormat account preference parameter. An attacker can leverage this by injecting a malicious JavaScript payload into the timeFormat preference. When a victim logs into the WebMail interface, the unsanitized timeFormat value is loaded and inserted into the Document Object Model (DOM), leading to script execution. This requires a multi-stage attack, potentially involving exploiting a separate issue or using compromised credentials to initially inject the payload.
Recommendations Update to version 10.5.57 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68643

Affected Products

Axigen Mail Server