logo

Crafting Emails with HTML Injection

ID: 62a40c59-c226-5f0e-9072-b386d5b11a7f

STIX ID: report--62a40c59-c226-5f0e-9072-b386d5b11a7f

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report describes how unencoded user input in HTML-enabled emails and certain request headers (e.g., X-Forwarded-For, Host) can be abused to inject HTML into outbound emails, hide or replace legitimate content, and craft malicious links—potentially leading to phishing and password-reset token leakage to attacker-controlled domains. It provides concrete examples, detection tips (viewing raw email source, base64 decoding), and remediation guidance such as output-encoding and disabling HTML email bodies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.