CVE Feed

    Dashboard / CVE / CVE-2021-47768

    CVE-2021-47768

    ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials.

    Published:Jan 15, 2026
    Last Modified:Jan 30, 2026
    EPS:Jan 15, 2026
    EPSS Score:0.00045
    CVSS Score:6.1

    Affected Products

    Vendor
    Cleidigh
    Product
    Importexporttools Ng
    Vendor
    Thundernest
    Product
    Importexporttools Ng

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High