Junglewise Threat Intelligence

CVE-2026-29965: HSC MailInspector XSS in WarningUrlPage.php

CVE-2026-29965 · Severity: info · CVSS 8.2 · Published 2026-05-18

Technologies: HSC Labs MailInspector.

Executive brief

HSC MailInspector, an email security gateway used to protect corporate communications from phishing and malware, contains a vulnerability in its web management interface. An attacker can exploit this by tricking a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login credentials, session hijacking, or the manipulation of sensitive security settings.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in HSC MailInspector v5.3.3-7 within the '/police/WarningUrlPage.php' endpoint. The root cause is the improper neutralization of user-supplied input, specifically failing to account for alternate or obfuscated JavaScript syntax (CWE-87). An unauthenticated remote attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's session. This can be used to bypass security controls, steal session tokens, or perform actions on behalf of the user. The vulnerability has been assigned a CVSS 3.1 base score of 8.2.

Affected products

  • HSC Labs MailInspector 5.3.3-7

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: advisory

References