Alinto SOGo Cross-Site Scripting Vulnerability in Versions 5.12.3 and 5.12.4

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Alinto SOGo versions 5.12.3 and 5.12.4. The issue arises in the web login interface, where the application fails to properly sanitize user input passed through the 'hint' URL parameter. This lack of proper encoding allows remote attackers to inject and execute arbitrary JavaScript in the context of the victim's browser. The vulnerability can be exploited by convincing users to visit a specially crafted URL that includes the malicious payload.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the affected user's browser, potentially leading to session hijacking or other malicious actions.

Reproduction

To reproduce this vulnerability, send a request to the SOGo login interface with a crafted 'hint' parameter that includes a JavaScript payload. The injected script will be executed in the context of the user's browser.

Added: Feb 24, 2026, 3:39 AM
Updated: Feb 24, 2026, 3:39 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.7
exploitability
7.5
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.