Описание
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/resolute | needs-triage | |
| jammy | needs-triage | |
| noble | DNE | |
| questing | ignored | end of life, was needs-triage |
| resolute | needs-triage |
Показывать по
6.3 Medium
CVSS3
Связанные уязвимости
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.
Уязвимость компонента поиска контактов программного обеспечения для совместной работы SOGo, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации
6.3 Medium
CVSS3