CVE-2026-23616 | GFI MailEssentials AI up to 22.3 Management Interface AntiSpoofing.aspx cross site scripting
A vulnerability marked as problematic has been reported in GFI MailEssentials AI up to 22.3. This vulnerability affects unknown code of the file /MailEssentials/pages/MailSecurity/AntiSpoofing.aspx of the component Management Interface. This manipulation of the argument ctl00$ContentPlaceHolder1$AntiSpoofingGeneral1$TxtSmtpDesc causes cross site scripting.
This vulnerability is tracked as CVE-2026-23616. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.