CVE-2024-34462Cross-site Scripting in Sogo

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 70.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 4

Description

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDalinto/sogo< 5.11.0
Debianalinto/sogo< 5.0.1-4+deb11u3+3

Patches

🔴Vulnerability Details

3
CVEList
CVE-2024-34462: Alinto SOGo through 52024-05-04
GHSA
GHSA-6m2f-g987-jc22: Alinto SOGo through 52024-05-04
OSV
CVE-2024-34462: Alinto SOGo through 52024-05-04

📋Vendor Advisories

2
Oracle
Oracle Oracle NoSQL Database Risk Matrix: Administration (Netty) — CVE-2023-344622024-01-15
Debian
CVE-2024-34462: sogo - Alinto SOGo through 5.10.0 allows XSS during attachment preview.2024
CVE-2024-34462 — Cross-site Scripting in Alinto Sogo | cvebase