CVE-2026-23615 | GFI MailEssentials AI up to 22.3 Email Exceptions Interface SenderPolicyFramework.aspx ctl00$ContentPlaceHolder1$pv4$txtEmailDescription cross site scripting
A vulnerability labeled as problematic has been found in GFI MailEssentials AI up to 22.3. This affects an unknown part of the file /MailEssentials/pages/MailSecurity/SenderPolicyFramework.aspx of the component Email Exceptions Interface. The manipulation of the argument ctl00$ContentPlaceHolder1$pv4$txtEmailDescription results in cross site scripting.
This vulnerability is identified as CVE-2026-23615. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.