MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| mailenable / mailenable | 6.0 | 6.90 |
| mailenable / mailenable | 7.0 | 7.62 |
| mailenable / mailenable | 8.00 | 8.64 |
| mailenable / mailenable | 9.0 | 9.83 |
| mailenable / mailenable | 10.00 | 10.24 |