CVE-2026-3054

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.347412 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.347412 Third Party Advisory VDB Entry
https://vuldb.com/?submit.757609 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:alinto:sogo:5.12.3:*:*:*:*:*:*:*
cpe:2.3:a:alinto:sogo:5.12.4:*:*:*:*:*:*:*

History

28 Feb 2026, 01:36

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en Alinto SOGo 5.12.3/5.12.4. Esto afecta a una función desconocida. Manipular el argumento 'hint' puede provocar un cross-site scripting. El ataque puede ser iniciado en remoto. El exploit está disponible públicamente y podría ser utilizado. El proveedor fue contactado con antelación sobre esta divulgación, pero no respondió de ninguna manera.
First Time Alinto
Alinto sogo
References () https://vuldb.com/?ctiid.347412 - () https://vuldb.com/?ctiid.347412 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.347412 - () https://vuldb.com/?id.347412 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.757609 - () https://vuldb.com/?submit.757609 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:alinto:sogo:5.12.3:*:*:*:*:*:*:*
cpe:2.3:a:alinto:sogo:5.12.4:*:*:*:*:*:*:*

24 Feb 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 03:16

Updated : 2026-02-28 01:36


NVD link : CVE-2026-3054

Mitre link : CVE-2026-3054

CVE.ORG link : CVE-2026-3054


JSON object : View

Products Affected

alinto

  • sogo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')