Vulnerability Description
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digitus | Inmailx | >= 3.21.0601, < 3.22.0101 |
Related Weaknesses (CWE)
References
- http://www.inmailx.com/products/inmailxProductVendor Advisory
- https://gist.github.com/0xVavaldi/9b7afbfe56938294480f7613805d3b7f
- http://www.inmailx.com/products/inmailxProductVendor Advisory
- https://gist.github.com/TheWorkingDeveloper/9b7afbfe56938294480f7613805d3b7f
FAQ
What is CVE-2022-27105?
CVE-2022-27105 is a vulnerability with a CVSS score of 5.4 (MEDIUM). InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to exec...
How severe is CVE-2022-27105?
CVE-2022-27105 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27105?
Check the references section above for vendor advisories and patch information. Affected products include: Digitus Inmailx.