Hi team,
most of the time, the Impact of HTML injection can be more than informative or a P5 therefore I believe the severity here shall be P4
at the minimum, the impact here can include
- The attacker steals the victim's IP by embedding an image.
- Phishing
- Exploitation of GET based CSRF etc
also, we already have
Server-Side Injection > Content Spoofing > Email HTML Injection
as P4, so it would make more sense to change this to a P4 as the severity here shall be higher or equal to the Email HTML Injection issue
( in HTML Content Injection there are more attack scenarios and direct impact on the application.)