CVE-2025-63499
MEDIUMAlinto SOGo < 5.12.4 - Cross-Site Scripting via Theme Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-63499. PoCs published by adminlove520, poblaguev-tot.
AI-analyzed exploit summary The repository contains only a minimal README with no exploit code, technical details, or functional PoC. It is a placeholder with no substantive content.
Description
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
Exploits (2)
The repository contains only a minimal README with no exploit code, technical details, or functional PoC. It is a placeholder with no substantive content.
This repository documents a reflected XSS vulnerability in SOGo's theme parameter, affecting versions <= 5.12.4. The exploit requires knowledge of the victim's email and an active session, with the payload delivered via a crafted URL.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N