cbcvebase.
CVE-2025-63498
published 2025-11-24

CVE-2025-63498: alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Affected

7 ranges
VendorProductVersion rangeFixed in
alintosogo
alintosogo>= 0 < 5.0.1-4+deb11u25.0.1-4+deb11u2
alintosogo>= 0 < 5.8.0-2+deb12u15.8.0-2+deb12u1
alintosogo>= 0 < 5.12.1-3+deb13u15.12.1-3+deb13u1
alintosogo>= 0 < 5.12.4-15.12.4-1
debiandebian_linux
debiansogo< sogo 5.8.0-2+deb12u1 (bookworm)sogo 5.8.0-2+deb12u1 (bookworm)

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM