CVE-2025-50340 – SOGo Webmail IDOR Email Spoofing

The following table lists the changes that have been made to the
CVE-2025-50340 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 04, 2025

    Action Type Old Value New Value
    Added Description An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system.
    Added Reference https://github.com/millad7/SOGo_web_mail-vulnerability-CVE-2025-50340
    Added Reference https://www.sogo.nu/
Share the Post:

Related Posts