alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
https://lists.debian.org/debian-lts-announce/2025/11/msg00029.html
https://github.com/xryptoh/CVE-2025-63498
https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.4
https://github.com/Alinto/sogo/commit/9e20190fad1a437f7e1307f0adcfe19a8d45184c