Описание
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 5.12.9-1 |
| esm-apps-legacy/xenial | needed | |
| esm-apps/bionic | needed | |
| esm-apps/focal | needed | |
| esm-apps/jammy | needed | |
| esm-apps/resolute | needed | |
| jammy | needed | |
| noble | DNE | |
| questing | needed | |
| resolute | needed |
Показывать по
10
Ссылки на источники
7.1 High
CVSS3
Связанные уязвимости
CVSS3: 7.1
nvd
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
CVSS3: 7.1
debian
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext ...
CVSS3: 7.1
github
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
7.1 High
CVSS3