ImportExportTools NG HTML Injection Vulnerability

Vulnerability

A persistent HTML injection vulnerability has been identified in the ImportExportTools NG version 10.0.4 for Mozilla Thunderbird. This vulnerability resides in the email export module, where the subject line of emails is not properly sanitized. As a result, remote attackers can inject malicious HTML that is executed during the export process, potentially compromising user data or session credentials.

Impact

Exploitation of this vulnerability allows for HTML injection, where injected HTML is executed in the context of the application, potentially leading to the execution of malicious scripts or the manipulation of exported data.

Reproduction

To reproduce this vulnerability, install Mozilla Thunderbird and the ImportExportTools NG version 10.0.4. Then, send an email to the target inbox with a crafted HTML payload in the subject line. After that, export the inbox content as HTML using the ImportExportTools NG extension. The injected HTML payload will execute in the exported file, demonstrating the vulnerability.

Remediation

Users are advised to update to ImportExportTools NG version 14.1.15, which addresses the HTML injection vulnerability by sanitizing and encoding subject content before export.

Added: Jan 15, 2026, 4:37 PM
Updated: Jan 15, 2026, 7:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.5
exploitability
5.4
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.