Several XSS vulnerabiltiies have been found in SOGo, a groupware server. CVE-2024-34462 XSS during attachment preview. CVE-2025-63499 Cross Site Scripting (XSS) via the theme parameter.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4434-1
The SOGo groupware server is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter, allowing arbitrary JavaScript to be executed when a user visits the authentication page. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4386-1
It was discovered that missing SAML signature validation in the SOGo groupware could result in impersonation attacks. For the oldstable distribution (buster), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5029-1
One security issue has been discovered in sogo. SOGo does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2707-1
Get the latest Linux and open source security news straight to your inbox.