PT-2026-21653 · Alinto · Alinto Sogo
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alinto SOGo versions 5.12.3 through 5.12.4
Description
A flaw exists in Alinto SOGo that allows for cross site scripting. The issue stems from manipulating the
hint argument within an unknown function. This can be triggered remotely. The exploit is publicly available. The vendor was contacted regarding this issue but did not respond.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alinto Sogo