ZeroHour

CVE-2016-6189

PoC
CVSS 3.1
4.3 medium
EPSS
1%p71
Published
()
Modified
Description

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

Vendors
alinto
Products
sogo
Weakness
CWE-184
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.