CVE-2022-4556
published 2022-12-16CVE-2022-4556: A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.56%
43.4th percentile
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alinto | sogo | < 5.8.0 | 5.8.0 |
| alinto | sogo | — | — |
| alinto | sogo | — | — |
| alinto | sogo | >= 0 < 5.8.0-1 | 5.8.0-1 |
| alinto | sogo | >= 0 < 5.8.0-1 | 5.8.0-1 |
| alinto | sogo | >= 0 < 5.8.0-1 | 5.8.0-1 |
| debian | sogo | < sogo 5.8.0-1 (bookworm) | sogo 5.8.0-1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxr5-ghr8-4787: A vulnerability was found in Alinto SOGo up to 5
ghsa_unreviewed·2022-12-22
CVE-2022-4556 [MEDIUM] CWE-79 GHSA-vxr5-ghr8-4787: A vulnerability was found in Alinto SOGo up to 5
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.
OSV
CVE-2022-4556: A vulnerability was found in Alinto SOGo up to 5
osv·2022-12-16·CVSS 6.1
CVE-2022-4556 [MEDIUM] CVE-2022-4556: A vulnerability was found in Alinto SOGo up to 5
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.
Debian
CVE-2022-4556: sogo - A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problemat...
vendor_debian·2022·CVSS 3.5
CVE-2022-4556 [LOW] CVE-2022-4556: sogo - A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problemat...
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipulation of the argument fullName leads to cross site scripting. The attack may be launched remotely. Upgrading to version 5.8.0 is able to address this issue. The name of the patch is efac49ae91a4a325df9931e78e543f707a0f8e5e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215960.
Scope: local
bookworm: resolved (fixed in 5.8.0-1)
bullseye: open
forky: resolved (fixed in 5.8.0-1)
sid: resolved (fixed in 5.8.0-1)
trixie: resolved (fixed in 5.8.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Alinto/sogo/commit/efac49ae91a4a325df9931e78e543f707a0f8e5ehttps://github.com/Alinto/sogo/releases/tag/SOGo-5.8.0https://vuldb.com/?id.215960https://github.com/Alinto/sogo/commit/efac49ae91a4a325df9931e78e543f707a0f8e5ehttps://github.com/Alinto/sogo/releases/tag/SOGo-5.8.0https://vuldb.com/?id.215960
2022-12-16
Published