vendor:
ImportExportTools NG
by:
Vulnerability Lab
4.2
CVSS
MEDIUM
Script Code Injection
79
CWE
Product Name: ImportExportTools NG
Affected Version From: ImportExportTools NG v10.0.4
Affected Version To: ImportExportTools NG v10.0.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2021
ImportExportTools NG 10.0.4 – HTML Injection
A persistent input validation vulnerability has been discovered in the official ImportExportTools NG 10.0.4 for mozilla thunderbird. The vulnerability allows remote attackers to inject malicious script codes to the application-side of the vulnerable module. The vulnerability is located in the `import/export` module of the application. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable module. The request method to inject is POST and the attack vector is located on the application-side.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable input parameters. Restrict the input and disallow special chars and script codes.