There are 5 open security issues in bookworm.
5 issues left for the package maintainer to handle:
- CVE-2023-48104:
(needs triaging)
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
- CVE-2024-24510:
(needs triaging)
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
- CVE-2024-34462:
(needs triaging)
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
- CVE-2025-63498:
(needs triaging)
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
- CVE-2025-63499:
(needs triaging)
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
You can find information about how to handle these issues in the security team's documentation.