VYPR

sogo

by Debian

Source repositories

CVEs (2)

  • CVE-2026-39179MedJul 8, 2026
    risk 0.34cvss 6.3epss 0.00

    A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.

  • CVE-2026-39178MedJul 8, 2026
    risk 0.34cvss 6.3epss 0.00

    A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.