Описание
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-63499
- https://email.example.com/SOGo/so/victim@example.com/Mail/view?theme=%27%3CScRiPt%20%3Ealert%289998%29%3C%2FScRiPt%3E
- https://email.victim.com/SOGo/so/victim@victim.com/Mail/view?theme=%27%3CScRiPt%20%3Ealert%289998%29%3C%2FScRiPt%3E
- https://github.com/poblaguev-tot/CVE-2025-63499
Связанные уязвимости
CVSS3: 6.1
ubuntu
2 месяца назад
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVSS3: 6.1
nvd
2 месяца назад
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVSS3: 6.1
debian
2 месяца назад
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the ...