SOGo是Alinto开源的一个非常快速且可扩展的现代协作套件。它提供日历、地址簿管理和功能齐全的 Webmail 客户端以及资源共享和权限处理。 SOGo 5.12.7版本存在SQL注入漏洞,该漏洞源于访问控制列表管理功能中addUserInAcls端点的uid参数存在SQL注入,可能导致认证用户提取数据库中的任意数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Alinto | SOGo Webmail | 5.12.8 |
unaffected |
≤ 5.12.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Alinto | SOGo Webmail | 5.12.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet