JustAppSec
HIGH SeverityCVSS 3.17.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

CVE-2026-46446

Last updated May 14, 2026 · Published May 14, 2026

← Back to list

Description

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.

Affected products

1 listed
  • Alinto:SOGo

Mappings

CWE

CWE-89

CAPEC

None listed.

Related


CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms

Need help?Get in touch.