What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.
Explanation of Vulnerability in Simple Terms
WPO365 Mail Integration for Office 365/Outlook versions up to 1.9.0 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted page. The vulnerability requires user interaction and network access but does not require authentication. Scope is changed, meaning the impact may extend beyond the vulnerable component.
What an attacker can do
Inject malicious scripts that run in a victim's browser to steal data or perform actions on their behalf.
Potential impact on your site
Users visiting affected pages could have their session data stolen or be tricked into performing unintended actions.
Conditions required to exploit
Victim must visit a crafted page; no authentication required. Attack requires network access and high attack complexity.
Key dates
External resources
Related vulnerabilities