XSS Vulnerability in SOGo Attachment Preview
CVE-2024-34462

6.1MEDIUM

Key Information:

Vendor

Alinto

Status
Vendor
CVE Published:
4 May 2024

What is CVE-2024-34462?

The Alinto SOGo email client is susceptible to a Cross-Site Scripting (XSS) vulnerability that occurs during the attachment preview feature. This flaw allows attackers to exploit the system by injecting malicious scripts into the previewed attachments, posing significant risks to user data and privacy. Users interacting with these attachments may inadvertently execute the malicious code, compromising their security. It is essential for users and organizations utilizing SOGo to apply available patches and security updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.