View Issue Details

IDProjectCategoryView StatusLast Update
0006158SOGoWeb Address Bookpublic2025-11-02 11:53
Reportervrubim Assigned To 
PriorityhighSeveritycrashReproducibilityalways
Status newResolutionopen 
Platform[Server] LinuxOSUbuntuOS Version16.04 LTS
Product Version5.12.4 
Summary0006158: Cross-Site Scripting (XSS) - Stored
Description

Stored Cross-Site Scripting occurs when an application receives data from an untrusted source and then includes that data in its subsequent HTTP responses in an insecure manner

It is possible to set other undefined values ​​in the category name, and to add XSS scripts.

Endpoint: /Preferences#!/addressbooks

Steps To Reproduce

see screenshots.

TagsSecurity

Activities

vrubim

vrubim

2025-10-31 14:58

reporter   ~0018365

screenshots addeds

4.png (39,228 bytes)   
4.png (39,228 bytes)   
3.png (122,891 bytes)   
3.png (122,891 bytes)   
2.png (41,422 bytes)   
2.png (41,422 bytes)   
1.png (114,466 bytes)   
1.png (114,466 bytes)   

Issue History

Date Modified Username Field Change
2025-10-31 14:48 vrubim New Issue
2025-10-31 14:48 vrubim Tag Attached: Security
2025-10-31 14:58 vrubim Note Added: 0018365
2025-10-31 14:58 vrubim File Added: 4.png
2025-10-31 14:58 vrubim File Added: 3.png
2025-10-31 14:58 vrubim File Added: 2.png
2025-10-31 14:58 vrubim File Added: 1.png