A vulnerability in MailEnable Enterprise Premium versions 10.55 and earlier has been identified that may allow authorized users to reset the passwords of other users in the same postoffice if mobile webadmin is accessible. Standard, Professional and Enterprise Editions are not affected.
Thanks to dninh for the discovery of this.
Version 10 Premium users can download the update from: https://www.mailenable.com/download.asp.
If your version is prior to version 10, then you can download the update from: https://www.mailenable.com/downloadprevious.asp.