Inout Mobile Webmail APP – Multiple Web Vulnerabilities
The bugs allow remote attackers to implement/inject malicious script code on the application side (persistent). Successful exploitation of the vulnerability can lead to session hijacking (manager/admin) or stable (persistent) context manipulation. Exploitation requires low user interaction & privileged user account. The persistent validation vulnerabilities are located in the new mail & contacts modules with the bound values to, bcc, cc. The bug can be exploited by remote attackers. The attacker is sending a malicious mail with vulnerable script code values as content. The admin or customer is watching the arriving mail and the persistent script code in To or Bcc inputs. The context will be executed (persistent) when the user, customer, or admin is processing to check his mails. A privileged user account can also use the bug to save it persistent for higher privileged user account exploitation.