CVE-2014-9905
MEDIUMSOGo < 2.1.1 - Cross-Site Scripting via Appointment Title or Contact Fields
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.
References (6)
Core 6
Core References
Patch x_refsource_confirm
https://github.com/inverse-inc/sogo/commit/80a09407652ec04e8c9fb6cb48e1029e69a15765
Mailing List, Patch, VDB Entry mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/07/09/3
Patch x_refsource_confirm
https://github.com/inverse-inc/sogo/commit/3a5e44e7eb8b390b67a8f8a83030b49606956501
Patch x_refsource_confirm
https://github.com/inverse-inc/sogo/commit/c94595ea7f0f843c2d7abf25df039b2bbe707625
Vendor Advisory x_refsource_confirm
https://sogo.nu/bugs/view.php?id=2598
Patch x_refsource_confirm
https://github.com/inverse-inc/sogo/commit/1a7fc2a0e90a19dfb1fce292ae5ff53aa513ade9
Scores
CVSS v3
6.1
EPSS
0.0122
EPSS Percentile
65.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
alinto/sogo
< 2.1.1
Published
Feb 17, 2017
Tracked Since
Feb 18, 2026