PT-2026-21653 · Alinto · Alinto Sogo
Erickfernandox
·
Published
2026-02-24
·
Updated
2026-02-28
·
CVE-2026-3054
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alinto SOGo versions 5.12.3 through 5.12.4
Description
A flaw exists in Alinto SOGo that allows for cross site scripting. The issue stems from manipulating the
hint argument within an unknown function. This can be triggered remotely. The exploit is publicly available. The vendor was contacted regarding this issue but did not respond.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alinto Sogo