CVE-2021-47768

Source
https://cve.org/CVERecord?id=CVE-2021-47768
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47768.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-47768
Published
2026-01-15T16:16:08.340Z
Modified
2026-03-14T08:43:10.385780Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials.

References

Affected packages

Git / github.com/thunderbird/import-export-tools-ng

Affected ranges

Type
GIT
Repo
https://github.com/thunderbird/import-export-tools-ng
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "10.0.4"
        }
    ]
}

Affected versions

v10.*
v10.0.4
v3.*
v3.3.2
v3.3.3-f1
v3.3.3-preformat
v4.*
v4.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47768.json"