CVE-2025-68721
- EPSS 0.01%
- Veröffentlicht 05.02.2026 00:00:00
- Zuletzt bearbeitet 13.02.2026 15:15:57
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates manag...
CVE-2025-68722
- EPSS 0.02%
- Veröffentlicht 05.02.2026 00:00:00
- Zuletzt bearbeitet 24.02.2026 18:14:24
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing reques...
CVE-2025-68643
- EPSS 0.03%
- Veröffentlicht 05.02.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 21:16:17
Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account preference parameter. Attackers can exploit this by deploying a multi-stage attack. In the first stage, a malicious JavaScript payloa...
- EPSS 0.02%
- Veröffentlicht 05.02.2026 00:00:00
- Zuletzt bearbeitet 13.02.2026 15:15:57
Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in th...
CVE-2024-50601
- EPSS 0.12%
- Veröffentlicht 11.11.2024 23:15:05
- Zuletzt bearbeitet 12.11.2024 16:35:22
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hijacking, data leakage, and fur...
CVE-2024-28589
- EPSS 0.12%
- Veröffentlicht 03.04.2024 08:15:49
- Zuletzt bearbeitet 21.11.2024 09:06:40
An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service ini...
CVE-2024-25080
- EPSS 0.07%
- Veröffentlicht 01.04.2024 09:15:50
- Zuletzt bearbeitet 21.11.2024 09:00:12
WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.
CVE-2020-26942
- EPSS 0.29%
- Veröffentlicht 21.03.2024 02:36:18
- Zuletzt bearbeitet 05.03.2025 18:25:53
An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.
CVE-2023-48974
- EPSS 6.58%
- Veröffentlicht 08.02.2024 01:15:26
- Zuletzt bearbeitet 17.06.2025 16:15:24
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.
CVE-2023-23566
- EPSS 0.7%
- Veröffentlicht 13.01.2023 04:15:09
- Zuletzt bearbeitet 07.04.2025 16:15:22
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or PO...