CVE-2026-29964
EUVD-2026-3078418.05.2026, 18:17
HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output encoding, allowing a remote attacker to execute arbitrary JavaScript code in the context of a victim's browser.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hsclabs | mailinspector | 5.3.3-7 |
𝑥
= Vulnerable software versions