CVE-2026-23610 | GFI MailEssentials AI up to 22.3 Management Interface Save Login cross site scripting
A vulnerability was found in GFI MailEssentials AI up to 22.3. It has been classified as problematic. This affects an unknown function of the file /MailEssentials/pages/MailSecurity/POP2Exchange.aspx/Save of the component Management Interface. This manipulation of the argument Login causes cross site scripting.
This vulnerability is handled as CVE-2026-23610. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.