View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0006195 | SOGo | Backend Mail | public | 2026-04-23 10:44 | 2026-05-26 15:42 |
| Reporter | David | Assigned To | qhivert | ||
| Priority | normal | Severity | minor | Reproducibility | always |
| Status | assigned | Resolution | open | ||
| Platform | [Server] Linux | OS | RHEL/CentOS | OS Version | 7 |
| Product Version | 5.12.6 | ||||
| Summary | 0006195: SOGoMailCustomFromEnabled = NO not enforced server-side | ||||
| Description | The configuration option | ||||
| Steps To Reproduce |
| ||||
| Additional Information | When | ||||
| Tags | No tags attached. | ||||
|
Seems like a serious security bug that allow SPAM distribution from SOGo, any workaround? |
|
|
Hello, SOGo is only a client of your SMTP server. It's him who allows or not authenticated user to send an email with such "from" address. There is a lot of legitimate case where the from is not the same as the authenticated user's mail. You have to configure your postfix/others to add protection for this. |
|
|
Dear David, I would follow the advice of Quentin and would check this over mailserver. We're using Mailcow docker from https://mailcow.email/ with integrated SOGo and can do all configurations and SPAM checks from there. The Bahnkonzept team from Dresden/Germany |
|
|
OK, no problem, will configure SMTP to solve this, thank you. Anyway, still in doubts - if there's a parameter advertised as "not to allow user to specify custom From," but it only disables a UI field without any server-side check, it looks like a misleading guarantee. |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-04-23 10:44 | David | New Issue | |
| 2026-05-18 09:36 | David | Note Added: 0018467 | |
| 2026-05-18 09:48 | qhivert | Note Added: 0018468 | |
| 2026-05-18 09:48 | qhivert | Assigned To | => qhivert |
| 2026-05-18 09:48 | qhivert | Status | new => feedback |
| 2026-05-20 20:15 | bahnkonzept | Note Added: 0018482 | |
| 2026-05-26 15:42 | David | Note Added: 0018486 | |
| 2026-05-26 15:42 | David | Status | feedback => assigned |