Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Woodyslum

#20774of 53,632
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-20429
6.1
2024-09-09
Alinto · Alinto Sogo · CVE-2024-24510
**Name of the Vulnerable Software and Affected Versions** Alinto SOGo versions prior to 5.10.0 **Description** A Cross Site Scripting issue exists in Alinto SOGo, allowing a remote attacker to execute arbitrary code via the import function to the mail component. This can be exploited by a remote attacker. **Recommendations** For versions prior to 5.10.0, update to version 5.10.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the import function in the mail component until a patch is available.
PT-2022-27574
6.1
2022-12-01
Alinto · Alinto Sogo · CVE-2022-4556
**Name of the Vulnerable Software and Affected Versions** Alinto SOGo versions up to 5.7.1 **Description** A vulnerability was found in the Identity Handler component, specifically in the function ` migrateMailIdentities` of the file `SoObjects/SOGo/SOGoUserDefaults.m`. The manipulation of the argument `fullName` leads to cross-site scripting. The attack may be launched remotely. **Recommendations** For Alinto SOGo versions up to 5.7.1, upgrade to version 5.8.0 to address this issue.