Impact
SOGo versions preceding 5.12.11 construct password‑reset URLs that use the client‑supplied Origin header as the authority. An unauthenticated attacker can supply a malicious Origin header when initiating a password reset request, causing the system to embed the password‑reset token in an email that points to the attacker’s domain. The attacker then obtains the token and can perform an account takeover. This flaw is an instance of credential reuse through weak origin handling (CWE‑640).
Affected Systems
All versions of Alinto SOGo released before 5.12.11 are affected. The vulnerability is present in any deployment that uses the legacy password‑reset flow without patching to 5.12.11 or newer. No specific patch release details beyond the mitigation path are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity flaw. The EPSS score of less than 1% shows that current exploitation activity is very low, and the vulnerability is not yet listed in CISA’s KEV catalog. It is an unauthenticated, remote flaw that can be exploited via a crafted HTTP request where the attacker controls the Origin header. The likely attack vector is a client‑side request that triggers a password reset email, which is then intercepted or redirected by the attacker. The consequences are full account takeover for the targeted user. The risk is elevated for environments that allow arbitrary Origin headers in the password reset path and do not enforce domain validation.
OpenCVE Enrichment