ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thundernest
Thundernest importexporttools Ng |
|
| Vendors & Products |
Thundernest
Thundernest importexporttools Ng |
Thu, 15 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials. | |
| Title | ImportExportTools NG 10.0.4 - HTML Injection | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-15T15:52:10.377Z
Updated: 2026-01-15T18:27:03.728Z
Reserved: 2026-01-14T14:39:44.735Z
Link: CVE-2021-47768
Updated: 2026-01-15T16:13:17.618Z
Status : Awaiting Analysis
Published: 2026-01-15T16:16:08.340
Modified: 2026-01-16T15:55:33.063
Link: CVE-2021-47768
No data.