Impact
A flaw in SOGo versions prior to 5.12.7 permits authenticated users to inject arbitrary SQL via the search parameter of the allContactSearch endpoint. The injection can lead to execution of any SQL statement against the underlying database, enabling data exfiltration, tampering, or other destructive actions. Consequently, confidentiality, integrity, and availability of stored data are at risk once an attacker gains authenticated access.
Affected Systems
The SOGo mail and calendar server software in all releases earlier than 5.12.7. Users with valid but ordinary SOGo credentials can trigger the flaw. The fix was implemented in commit 1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21 and shipped in 5.12.7.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not yet cataloged in CISA KEV. The CVSS score of 6.3 indicates moderate severity. The flaw requires authentication; attackers need valid credentials before exploitation. Once authenticated, the ability to inject arbitrary SQL gives the attacker extensive control over the database, increasing the potential impact. Although exploitation is less likely due to low EPSS, the risk remains high for organizations that have not yet applied the 5.12.7 update.
OpenCVE Enrichment