CVE-2026-23606 | GFI MailEssentials AI up to 22.3 Management Interface advancedfiltering.aspx ctl00$ContentPlaceHolder1$pv1$txtRuleName cross site scripting
A vulnerability, which was classified as problematic, has been found in GFI MailEssentials AI up to 22.3. This issue affects some unknown processing of the file /MailEssentials/pages/MailSecurity/advancedfiltering.aspx of the component Management Interface. Performing a manipulation of the argument ctl00$ContentPlaceHolder1$pv1$txtRuleName results in cross site scripting.
This vulnerability is reported as CVE-2026-23606. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.