CVE-2023-39223: A.k.i Software Pmam.exe

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability exists in CGIs included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Affected products

  • A.k.i Software Pmam.exe: up to and including 2.5.1.1411
  • A.k.i Software Pmc.exe: up to and including 2.5.1.720
  • A.k.i Software Pmum.exe Pro + IMAP4 Edition / Enterprise Edition: up to and including 2.5.1.25454
  • A.k.i Software Pmum.exe Pro Edition: up to and including 2.5.1.25452
  • A.k.i Software Pmum.exe Standard + IMAP4 Edition: up to and including 2.5.1.25453
  • A.k.i Software Pmum.exe Standard Edition: up to and including 2.5.1.25451

Published 2024-03-18. Last modified 2026-06-17.