CVE-2015-5395: CSRF
Published Sep 20, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
Affected Software
5 affected componentsFixes available
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Alinto SOGo<3.1.0
debian/sogo
5.0.1-4+deb11u15.0.1-4+deb11u35.8.0-2+deb12u25.12.1-3+deb13u15.12.4-1.2
Remediation
Patch Available
Patch Available
Event History
Sep 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 18, 2026
Data Sourced
via Debian·11:02 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-5395?
CVE-2015-5395 has a medium severity rating due to its potential for exploitation via cross-site request forgery.
2
How do I fix CVE-2015-5395?
To fix CVE-2015-5395, upgrade to SOGo version 3.1.0 or later to eliminate the vulnerability.
3
What software is affected by CVE-2015-5395?
CVE-2015-5395 affects SOGo versions prior to 3.1.0 along with several Debian versions.
4
What type of vulnerability is CVE-2015-5395?
CVE-2015-5395 is a cross-site request forgery (CSRF) vulnerability.
5
Is CVE-2015-5395 exploitable remotely?
Yes, CVE-2015-5395 can be exploited remotely by an attacker targetting users of the affected software.