Description
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.
References
http://www.inmailx.com/products/inmailx
ProductVendor Advisory
http://www.inmailx.com/products/inmailx
ProductVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-07-26T20:15:10.753Z
3 years agoLast modified
2024-11-21T05:55:08.457Z
1 year ago