CVE-2024-34462: XSS
Published May 4, 2024
·Updated
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
Affected Software
3 affected componentsFixes available
Alinto SOGo<5.10.0
Alinto SOGo<5.11.0
debian/sogo<=5.0.1-4+deb11u1
5.0.1-4+deb11u35.8.0-2+deb12u25.8.0-2+deb12u35.12.1-3+deb13u15.12.1-3+deb13u25.12.9-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.0.1-4+deb11u3Fixed in 5.8.0-2+deb12u2Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u1Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1
Event History
May 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 6, 2026
Data Sourced
via Debian·01:33 PM
DescriptionAffected Software
Data Sourced
via Launchpad·01:33 PM
Description
Jul 7, 2026
Data Sourced
via Ubuntu·01:34 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34462?
The severity of CVE-2024-34462 is classified as moderate due to its potential for cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2024-34462?
To fix CVE-2024-34462, update SOGo to a version later than 5.10.0 that addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2024-34462?
CVE-2024-34462 is a cross-site scripting (XSS) vulnerability that occurs during attachment previews in SOGo.
4
Which versions of Alinto SOGo are affected by CVE-2024-34462?
CVE-2024-34462 affects Alinto SOGo versions up to and including 5.10.0.
5
What impact does CVE-2024-34462 have on users?
CVE-2024-34462 could allow an attacker to execute arbitrary scripts in the context of a user's browser, potentially compromising user data.