CVE-2025-63498: XSS
Published Nov 24, 2025
·Updated
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
Affected Software
4 affected componentsFixes available
Alinto SOGo
Alinto SOGo=5.12.3
Debian Debian Linux=11.0
debian/sogo<=5.0.1-4+deb11u1
5.0.1-4+deb11u35.8.0-2+deb12u25.8.0-2+deb12u35.12.1-3+deb13u15.12.1-3+deb13u25.12.9-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.0.1-4+deb11u3Fixed in 5.8.0-2+deb12u2Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u1Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 7, 2026
Data Sourced
via Ubuntu·01:34 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·01:35 PM
Description
Data Sourced
via Debian·01:35 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63498?
CVE-2025-63498 is classified as a moderate severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-63498?
To fix CVE-2025-63498, validate and sanitize the input for the "userName" parameter to mitigate XSS risks.
3
Which software versions are affected by CVE-2025-63498?
CVE-2025-63498 affects Alinto SOGo version 5.12.3.
4
What type of vulnerability is CVE-2025-63498?
CVE-2025-63498 is a Cross Site Scripting (XSS) vulnerability that can allow attackers to inject malicious scripts.
5
What impact does CVE-2025-63498 have on users?
CVE-2025-63498 can potentially allow an attacker to execute scripts in a user's browser, compromising their session and privacy.