CVE-2022-27105 describes a Cross-Site Scripting (XSS) vulnerability in the InMailX Outlook Plugin versions prior to 3.22.0101, affecting products from digitus inmailx. The vulnerability stems from unsanitized InMailX Connection names within the Outlook tab. This allows a local user or network administrator to execute malicious HTML or JavaScript code within other users' Outlook environments. With a CVSS score of 5.4 (Medium), the attack vector is network-based with low attack complexity, requiring user interaction (UI:R) and low privileges (PR:L). A successful exploit could lead to low confidentiality and integrity impacts (C:L, I:L) without affecting availability (A:N). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.21.0601, < 3.22.0101CPE matchmatch criteria | cpe:2.3:a:digitus:inmailx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.