CVE-2026-23609 | GFI MailEssentials AI up to 22.3 Management Interface PerimeterSMTPServers.aspx ctl00$ContentPlaceHolder1$pv3$txtDescription cross site scripting
A vulnerability was found in GFI MailEssentials AI up to 22.3 and classified as problematic. The impacted element is an unknown function of the file /MailEssentials/pages/MailSecurity/PerimeterSMTPServers.aspx of the component Management Interface. The manipulation of the argument ctl00$ContentPlaceHolder1$pv3$txtDescription results in cross site scripting.
This vulnerability is known as CVE-2026-23609. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.