CVE-2025-63499: XSS
Published Dec 4, 2025
·Updated
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
Affected Software
3 affected componentsFixes available
Alinto SOGo
Alinto SOGo<=5.12.4
debian/sogo<=5.0.1-4+deb11u1
5.0.1-4+deb11u35.8.0-2+deb12u25.8.0-2+deb12u35.12.1-3+deb13u15.12.1-3+deb13u25.12.9-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.0.1-4+deb11u3Fixed in 5.8.0-2+deb12u2Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u1Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1
Event History
Dec 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Jul 6, 2026
Data Sourced
via Launchpad·01:33 PM
Description
Data Sourced
via Debian·01:33 PM
DescriptionAffected Software
Jul 7, 2026
Data Sourced
via Ubuntu·01:34 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63499?
CVE-2025-63499 is considered a moderate severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2025-63499?
To fix CVE-2025-63499, validate and sanitize the theme parameter to prevent XSS injections.
3
What software versions are affected by CVE-2025-63499?
CVE-2025-63499 affects Alinto Sogo version 5.12.3.
4
What type of vulnerability is CVE-2025-63499?
CVE-2025-63499 is categorized as a Cross Site Scripting (XSS) vulnerability.
5
Can CVE-2025-63499 be exploited remotely?
Yes, CVE-2025-63499 can be exploited remotely by crafting malicious requests that include a payload in the theme parameter.