View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0006158 | SOGo | Web Address Book | public | 2025-10-31 14:48 | 2026-01-14 16:19 |
| Reporter | vrubim | Assigned To | qhivert | ||
| Priority | high | Severity | crash | Reproducibility | always |
| Status | feedback | Resolution | open | ||
| Platform | [Server] Linux | OS | Ubuntu | OS Version | 16.04 LTS |
| Product Version | 5.12.4 | ||||
| Summary | 0006158: Cross-Site Scripting (XSS) - Stored | ||||
| Description | Stored Cross-Site Scripting occurs when an application receives data from an untrusted source and then includes that data in its subsequent HTTP responses in an insecure manner It is possible to set other undefined values in the category name, and to add XSS scripts. Endpoint: /Preferences#!/addressbooks | ||||
| Steps To Reproduce | see screenshots. | ||||
| Tags | Security | ||||
|
screenshots addeds |
|
|
Hello, |
|
|
qhivert what means "next nightly" ? I can't see any new release version on github "releases or tags" . |
|
|
This is the version that is build every night witht the latests commit in our repo. So the fix is already in it. |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-10-31 14:48 | vrubim | New Issue | |
| 2025-10-31 14:48 | vrubim | Tag Attached: Security | |
| 2025-10-31 14:58 | vrubim | Note Added: 0018365 | |
| 2025-10-31 14:58 | vrubim | File Added: 4.png | |
| 2025-10-31 14:58 | vrubim | File Added: 3.png | |
| 2025-10-31 14:58 | vrubim | File Added: 2.png | |
| 2025-10-31 14:58 | vrubim | File Added: 1.png | |
| 2025-12-16 09:27 | qhivert | Note Added: 0018391 | |
| 2025-12-16 09:27 | qhivert | Assigned To | => qhivert |
| 2025-12-16 09:27 | qhivert | Status | new => feedback |
| 2026-01-14 15:47 | vrubim | Note Added: 0018399 | |
| 2026-01-14 15:47 | vrubim | Status | feedback => assigned |
| 2026-01-14 16:19 | qhivert | Note Added: 0018400 | |
| 2026-01-14 16:19 | qhivert | Status | assigned => feedback |