5.4
CVSSv3

CVE-2020-27509

Published: 26/06/2022 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an malicious user to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs into their mailbox.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

galaxkey galaxkey