MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users).
| Software | From | Fixed in |
|---|---|---|
| mailenable / mailenable | 6.0 | 6.90 |
| mailenable / mailenable | 7.0 | 7.62 |
| mailenable / mailenable | 8.00 | 8.64 |
| mailenable / mailenable | 9.0 | 9.83 |
| mailenable / mailenable | 10.00 | 10.24 |