Home

Description

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-24 | Updated 2025-11-28 | Assigner mitre

References

lists.debian.org/debian-lts-announce/2025/11/msg00029.html

github.com/...ommit/9e20190fad1a437f7e1307f0adcfe19a8d45184c

github.com/xryptoh/CVE-2025-63498

github.com/Alinto/sogo/releases/tag/SOGo-5.12.4

cve.org (CVE-2025-63498)

nvd.nist.gov (CVE-2025-63498)

Download JSON