CVE-2026-23607 | GFI MailEssentials AI up to 22.3 Management Interface Whitelist.aspx ctl00$ContentPlaceHolder1$pv1$txtDescription cross site scripting
A vulnerability, which was classified as problematic, was found in GFI MailEssentials AI up to 22.3. Impacted is an unknown function of the file /MailEssentials/pages/MailSecurity/Whitelist.aspx of the component Management Interface. Executing a manipulation of the argument ctl00$ContentPlaceHolder1$pv1$txtDescription can lead to cross site scripting.
This vulnerability appears as CVE-2026-23607. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.