Cross-Site Scripting Vulnerability in Alinto SOGo Webmail
CVE-2026-8496
6.1MEDIUM
What is CVE-2026-8496?
A cross-site scripting vulnerability exists in Alinto SOGo version 5.12.7, allowing for arbitrary JavaScript execution within the webmail interface. This vulnerability arises when SVG content embedded in the description field of an ICS calendar invitation is inadequately sanitized. A remote attacker can exploit this issue to execute JavaScript in the victim's browser during the viewing of a malicious calendar invite. Successful exploitation may lead to unauthorized access to the mailbox, theft of emails and contacts, session hijacking, and other actions that an authenticated user is permitted to perform.
Affected Version(s)
SOGo 0 < 5.12.8
