Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Arseniy Poblaguev

#43112of 53,635
6.1Total CVSS
Vulnerabilities · 1
PT-2025-49122
6.1
2025-01-01
Unknown · Alinto Sogo · CVE-2025-63499
**Name of the Vulnerable Software and Affected Versions** Alinto Sogo version 5.12.3 **Description** Alinto Sogo 5.12.3 is susceptible to Cross Site Scripting (XSS) attacks. The issue is located in the handling of the `theme` parameter. Successful exploitation could allow an attacker to inject malicious scripts into web pages viewed by other users. **Recommendations** Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize or encode the `theme` parameter to prevent the execution of malicious scripts.