CVE-2020-22402
published 2023-06-14CVE-2020-22402: Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email…
PriorityP422medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.38%
30.5th percentile
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alinto | sogo | >= 0 < 4.3.2-1 | 4.3.2-1 |
| alinto | sogo | >= 0 < 4.3.2-1 | 4.3.2-1 |
| alinto | sogo | >= 0 < 4.3.2-1 | 4.3.2-1 |
| alinto | sogo | >= 0 < 4.3.2-1 | 4.3.2-1 |
| alinto | sogo_web_mail | < 4.3.1 | 4.3.1 |
| debian | sogo | < sogo 4.3.2-1 (bookworm) | sogo 4.3.2-1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8jg-9q68-vxjp: Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4
ghsa_unreviewed·2023-06-14
CVE-2020-22402 [MEDIUM] CWE-79 GHSA-f8jg-9q68-vxjp: Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
OSV
CVE-2020-22402: Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4
osv·2023-06-14·CVSS 6.1
CVE-2020-22402 [MEDIUM] CVE-2020-22402: Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
Debian
CVE-2020-22402: sogo - Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows at...
vendor_debian·2020·CVSS 6.1
CVE-2020-22402 [MEDIUM] CVE-2020-22402: sogo - Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows at...
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
Scope: local
bookworm: resolved (fixed in 4.3.2-1)
bullseye: resolved (fixed in 4.3.2-1)
forky: resolved (fixed in 4.3.2-1)
sid: resolved (fixed in 4.3.2-1)
trixie: resolved (fixed in 4.3.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-14
Published