CVE-2016-6189: Alinto Sogo

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

Affected products

  • Alinto Sogo: before 2.3.12 (fixed in 2.3.12); from 3.0.0, before 3.1.1 (fixed in 3.1.1)

Published 2017-02-17. Last modified 2026-06-17.