Executive brief
SOGo, an open-source collaborative groupware server, is vulnerable to a security flaw that could allow unauthorized access to its underlying database. This issue specifically affects organizations using PostgreSQL or those storing user passwords in plain text. An attacker could potentially exploit this to steal sensitive user data, modify account information, or disrupt email and calendar services.
Technical details
A SQL injection vulnerability exists in SOGo's SQLSource component due to improper neutralization of special elements in SQL commands. The flaw is primarily located in the credential handling logic, specifically within the `checkLogin` and password encryption routines in `SQLSource.m`. When PostgreSQL is used as a user source, or when other SQL databases (like MariaDB) are used with plain-text password algorithms (none, plain, or cleartext), attackers can inject malicious SQL via login fields. The fix involves migrating from manual string replacement of single quotes to using proper SQL adaptors and `EOQualifier` objects to safely handle parameters. This is a network-based attack that typically requires low privileges but high complexity due to specific configuration requirements.
Affected products
- Alinto SOGo before 5.12.7
Timeline
- 2026-03-24: patched: Fix committed to upstream repository
- 2026-03-30: advisory: SOGo v5.12.7 released with security warning
- 2026-05-14: disclosed: CVE-2026-46445 published