SOGo是一个非常快速且可扩展的现代协作套件。它提供日历、地址簿管理和功能齐全的 Webmail 客户端以及资源共享和权限处理。 SOGo 5.7.1及以前版本存在安全漏洞,该漏洞源于其Identity Handler组件的SoObjects/SOGo/SOGoUserDefaults.m文件中的_migrateMailIdentities函数对参数fullName的操作允许攻击者实现跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | 📄Official disclosure of CVE-2022-4556 — Stored Cross-Site Scripting (XSS) vulnerability in SOGo Webmail v5.7.1, discovered by Ashkan Rafiee and Mostafa Abbasi. Includes full writeup and reproduction steps. | https://github.com/AshkanRafiee/CVE-2022-4556 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet