Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-48104 — Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies. | Kitploit
Tools/GitHubGitHub/e1tex/cve-2023-48104
Vulnerability AnalysisExploitationWeb Application ExploitationPhishingWeb Security
GitHube1tex/cve-2023-48104

CVE-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

View Repository
82 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-48104

HTML Injection in Alinto/SOGo Web Client

Vendor of Product

Alinto

Vulnerability Type

HTML Injection

Affected Versions

SOGo Web Mail < 5.9.1

Attack Vectors

Phishing - In the body of the message, you can inject a malicious form that will send the entered data to the attacker.

Additional Information

The fix to prevent form tag in mail body has been made -> https://github.com/Alinto/sogo/commit/7481ccf37087c3f456d7e5a844da01d0f8883098

Discoverer

Spiridonov Ivan/E1tex

PoC

For demonstration purposes only. PoC Exploit works on SOGo vulnerable clients.

Download Tool